GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-06-10 17:43:45 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST750LM0 rev.2AR1 698,64GB Running: 1yiio2q8.exe; Driver: C:\Users\Ewa\AppData\Local\Temp\pxtiipog.sys ---- User code sections - GMER 2.2 ---- .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 000000004a560480 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 000000004a560470 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 000000004a560360 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 000000004a560490 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 000000004a5603d0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 000000004a560310 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 000000004a5603a0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 000000004a560380 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffffd30d4490} .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 000000004a5602d0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 000000004a5602c0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 000000004a560300 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 000000004a5603b0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 000000004a560440 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 000000004a5603e0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 000000004a560220 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 000000004a5604a0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 000000004a560390 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 000000004a5602e0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 000000004a560340 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 000000004a560280 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 000000004a5602a0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 000000004a5603c0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 000000004a560320 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 000000004a560410 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 000000004a560230 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 000000004a5603f0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 000000004a5601d0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 000000004a560240 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 000000004a5604b0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 000000004a5604c0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 000000004a5602f0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 000000004a560350 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 000000004a560290 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 000000004a5602b0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 000000004a560370 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 000000004a560330 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 000000004a560460 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 000000004a560420 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 000000004a560250 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 000000004a560260 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 000000004a560400 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 000000004a5601e0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 000000004a560200 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 000000004a5601f0 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 000000004a560430 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 000000004a560450 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 000000004a560210 .text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 000000004a560270 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\wininit.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000040480 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000040470 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000040360 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000040490 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000403d0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000040310 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000403a0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000040380 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88bb4490} .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000402d0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000402c0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000040300 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000403b0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000040440 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000403e0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000040220 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000404a0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000040390 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000402e0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000040340 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000040280 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000402a0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000403c0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000040320 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000040410 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000040230 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000403f0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000401d0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000040240 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000404b0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000404c0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000402f0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000040350 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000040290 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000402b0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000040370 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000040330 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000040460 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000040420 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000040250 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000040260 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000040400 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000401e0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000040200 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000401f0 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000040430 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000040450 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000040210 .text C:\Windows\system32\csrss.exe[704] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000040270 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\services.exe[740] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Windows\system32\lsass.exe[756] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\lsm.exe[764] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\winlogon.exe[832] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[912] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\nvvsvc.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[152] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Windows\System32\svchost.exe[532] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[1052] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1348] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000060480 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000060470 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000060360 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000060490 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000603d0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000060310 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000603a0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000060380 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88bd4490} .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000602d0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000602c0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000060300 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000603b0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000060440 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000603e0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000060220 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000604a0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000060390 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000602e0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000060340 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000060280 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000602a0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000603c0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000060320 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000060410 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000060230 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000603f0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000601d0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000060240 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000604b0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000604c0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000602f0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000060350 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000060290 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000602b0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000060370 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000060330 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000060460 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000060420 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000060250 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000060260 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000060400 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000601e0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000060200 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000601f0 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000060430 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000060450 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000060210 .text C:\Windows\system32\nvvsvc.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000060270 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[1572] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\spoolsv.exe[1804] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[2016] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\CxAudMsg64.exe[1096] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\svchost.exe[1740] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Intel\iCLS Client\HeciServer.exe[2112] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe[2332] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[2428] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[2464] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2844] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[2880] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[3052] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\svchost.exe[2776] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\taskhost.exe[3892] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef3772460 5 bytes JMP 000007fefd3902d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\d3d9.dll!Direct3DCreate9 000007fef37a96b0 6 bytes JMP 000007fefd390298 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef8e5dc88 5 bytes JMP 000007fef8e300d8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe[3904] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef8e5de10 5 bytes JMP 000007fef8e30110 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef8e5dc88 5 bytes JMP 000007fef8e300d8 .text C:\Windows\system32\Dwm.exe[4012] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef8e5de10 5 bytes JMP 000007fef8e30110 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\Explorer.EXE[4020] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000040480 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000040470 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000040360 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000040490 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000403d0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000040310 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000403a0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000040380 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88bb4490} .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000402d0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000402c0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000040300 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000403b0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000040440 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000403e0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000040220 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000404a0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000040390 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000402e0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000040340 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000040280 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000402a0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000403c0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000040320 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000040410 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000040230 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000403f0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000401d0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000040240 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000404b0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000404c0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000402f0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000040350 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000040290 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000402b0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000040370 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000040330 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000040460 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000040420 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000040250 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000040260 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000040400 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000401e0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000040200 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000401f0 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000040430 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000040450 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000040210 .text C:\Windows\system32\conhost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000040270 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe[3372] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files\Elantech\ETDCtrl.exe[3428] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1496] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Windows\system32\taskeng.exe[3688] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3980] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\SearchIndexer.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2004] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[1016] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\igfxtray.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\hkcmd.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Windows\System32\igfxpers.exe[4260] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000000f736f6 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4456] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\Elantech\ETDCtrlHelper.exe[4560] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef3772460 5 bytes JMP 000007fefd3902d0 .text C:\Program Files\Logitech Gaming Software\LCore.exe[4696] C:\Windows\system32\d3d9.dll!Direct3DCreate9 000007fef37a96b0 6 bytes JMP 000007fefd390298 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Users\Ewa\AppData\Local\MyComGames\MyComGames.exe[4920] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe[4972] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE[5032] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[1600] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[5040] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe[1908] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\USB Camera2\VM332_STI.EXE[5112] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe[5364] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\LockKey\LockKey.exe[5508] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\ole32.DLL!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\ole32.DLL!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe[5532] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076898791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075621401 2 bytes JMP 768bb263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075621419 2 bytes JMP 768bb38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075621431 2 bytes JMP 769390f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007562144a 2 bytes CALL 768948ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000756214dd 2 bytes JMP 769389ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000756214f5 2 bytes JMP 76938bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007562150d 2 bytes JMP 769388e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075621525 2 bytes JMP 76938caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007562153d 2 bytes JMP 768afce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075621555 2 bytes JMP 768b6937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007562156d 2 bytes JMP 769391a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075621585 2 bytes JMP 76938d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007562159d 2 bytes JMP 769388a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000756215b5 2 bytes JMP 768afd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000756215cd 2 bytes JMP 768bb324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000756216b2 2 bytes JMP 7693906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000756216bd 2 bytes JMP 76938839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5808] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\svchost.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075688a39 5 bytes JMP 0000000074982b20 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076d35e75 5 bytes JMP 0000000074982ae0 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076d69cbb 5 bytes JMP 0000000074982a70 .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5924] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\DllHost.exe[2420] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Windows\system32\wbem\unsecapp.exe[5264] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\system32\wbem\wmiprvse.exe[6120] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Windows\System32\svchost.exe[5824] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 0000000000070480 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 0000000000070470 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 0000000000070360 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 0000000000070490 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000000703d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 0000000000070310 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000000703a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 0000000000070380 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0xffffffff88be4490} .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000000702d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000000702c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 0000000000070300 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000000703b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 0000000000070440 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000000703e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 0000000000070220 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000000704a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 0000000000070390 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000000702e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 0000000000070340 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 0000000000070280 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000000702a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000000703c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 0000000000070320 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 0000000000070410 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 0000000000070230 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000000703f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000000701d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 0000000000070240 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000000704b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000000704c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000000702f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 0000000000070350 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 0000000000070290 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000000702b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 0000000000070370 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 0000000000070330 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 0000000000070460 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 0000000000070420 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 0000000000070250 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 0000000000070260 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 0000000000070400 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000000701e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 0000000000070200 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000000701f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 0000000000070430 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 0000000000070450 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 0000000000070210 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[6008] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 0000000000070270 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007748bbe0 5 bytes JMP 00000000775f0480 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007748bc30 5 bytes JMP 00000000775f0470 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007748bd90 5 bytes JMP 00000000775f0360 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007748bde0 5 bytes JMP 00000000775f0490 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007748bdf0 5 bytes JMP 00000000775f03d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007748bea0 5 bytes JMP 00000000775f0310 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007748bed0 5 bytes JMP 00000000775f03a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007748bef0 1 byte JMP 00000000775f0380 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 000000007748bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007748bf30 5 bytes JMP 00000000775f02d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007748bfb0 5 bytes JMP 00000000775f02c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007748bfd0 5 bytes JMP 00000000775f0300 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007748c010 5 bytes JMP 00000000775f03b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 000000007748c050 5 bytes JMP 00000000775f0440 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007748c060 5 bytes JMP 00000000775f03e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007748c1c0 5 bytes JMP 00000000775f0220 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007748c380 5 bytes JMP 00000000775f04a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007748c3b0 5 bytes JMP 00000000775f0390 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007748c490 5 bytes JMP 00000000775f02e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007748c4a0 5 bytes JMP 00000000775f0340 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007748c500 5 bytes JMP 00000000775f0280 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007748c590 5 bytes JMP 00000000775f02a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007748c5b0 5 bytes JMP 00000000775f03c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007748c5c0 5 bytes JMP 00000000775f0320 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007748c630 5 bytes JMP 00000000775f0410 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007748c660 5 bytes JMP 00000000775f0230 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007748c800 5 bytes JMP 00000000775f03f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007748c920 5 bytes JMP 00000000775f01d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007748c9e0 5 bytes JMP 00000000775f0240 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007748ca10 5 bytes JMP 00000000775f04b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007748ca20 5 bytes JMP 00000000775f04c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007748ca50 5 bytes JMP 00000000775f02f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007748ca60 5 bytes JMP 00000000775f0350 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007748cac0 5 bytes JMP 00000000775f0290 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007748cb10 5 bytes JMP 00000000775f02b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007748cb40 5 bytes JMP 00000000775f0370 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007748cb50 5 bytes JMP 00000000775f0330 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007748ce40 5 bytes JMP 00000000775f0460 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 000000007748cfa0 5 bytes JMP 00000000775f0420 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007748d040 5 bytes JMP 00000000775f0250 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007748d050 5 bytes JMP 00000000775f0260 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007748d060 5 bytes JMP 00000000775f0400 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007748d220 5 bytes JMP 00000000775f01e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007748d230 5 bytes JMP 00000000775f0200 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007748d2a0 5 bytes JMP 00000000775f01f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007748d300 5 bytes JMP 00000000775f0430 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007748d310 5 bytes JMP 00000000775f0450 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007748d320 5 bytes JMP 00000000775f0210 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[4364] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007748d400 5 bytes JMP 00000000775f0270 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076891f0e 7 bytes JMP 0000000074983c50 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076895bad 7 bytes JMP 0000000074984290 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000768a1431 7 bytes JMP 0000000074983ea0 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000768aea85 7 bytes JMP 0000000074983c40 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 000000007693906c 7 bytes JMP 00000000749836c0 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000769390f1 5 bytes JMP 0000000074983770 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076939447 5 bytes JMP 00000000749836d0 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000764b1e4c 5 bytes JMP 0000000074983680 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000764b1efa 5 bytes JMP 0000000074983640 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000764b2bdc 5 bytes JMP 0000000074983780 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000764b2e7e 5 bytes JMP 0000000074983480 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007642d2b4 5 bytes JMP 0000000074982c60 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007642d4ee 5 bytes JMP 0000000074982c70 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075694582 5 bytes JMP 0000000074983400 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000756ae587 5 bytes JMP 0000000074983470 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000756d08ab 5 bytes JMP 0000000074982960 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000756e7b24 5 bytes JMP 00000000749833e0 .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 12 0000000074e6100c 1 byte [11] .text C:\Users\Ewa\Downloads\1yiio2q8.exe[6740] C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll!Detoured + 14 0000000074e6100e 1 byte [4C] .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a3e0 7 bytes JMP 000000006fff0228 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333ef0 5 bytes JMP 000000006fff0180 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734fff0 5 bytes JMP 000000006fff01b8 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f3e0 5 bytes JMP 000000006fff0110 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389c70 7 bytes JMP 000000006fff00d8 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077399700 5 bytes JMP 000000006fff0148 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b8aa0 7 bytes JMP 000000006fff01f0 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3a32f0 7 bytes JMP 000007fefd3900d8 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3aaa60 5 bytes JMP 000007fefd390180 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3aac00 5 bytes JMP 000007fefd390110 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3b9ac0 5 bytes JMP 000007fefd390148 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe018a00 8 bytes JMP 000007fefd3901f0 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe01be60 8 bytes JMP 000007fefd3901b8 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe1e6d10 11 bytes JMP 000007fefd390228 .text C:\Windows\System32\osk.exe[7008] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe1fb4f0 7 bytes JMP 000007fefd390260 ---- Threads - GMER 2.2 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [304:4800] 000007fefb7d2af4 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [304:4948] 000007feef418f70 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [304:5092] 000007fef9605124 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\74e5439099b2 (not active ControlSet) Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74e5439099b2 Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\74e5439099b2 (not active ControlSet) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer@CleanShutdown 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced@Hidden 2 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ApplicationDestinations@MaxEntries 15 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}\Enum@ Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew@Classes .bmp?.contact?.jnt?.library-ms?.lnk?.rtf?.txt?.zip?Briefcase?Folder? Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithList Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithList Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithList@a NOTEPAD.EXE Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini\OpenWithList@MRUList a Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice@Progid WindowsLive.PhotoGallery.jpg.15.4 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\OpenWithList@MRUList a Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList@MRUList a Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wim Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wim\OpenWithList Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WTV\OpenWithList Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WTV\OpenWithList@a ehshell.exe Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WTV\OpenWithList@MRUList a Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ini Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ini@0 0x49 0x00 0x6E 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ini@MRUListEx 0x01 0x00 0x00 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ini@1 0x4C 0x00 0x61 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.wtv Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.wtv@0 0x77 0x00 0x69 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.wtv@MRUListEx 0x00 0x00 0x00 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2@FavoritesRemovedChanges 6 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband@FavoritesChanges 7 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband@FavoritesRemovedChanges 6 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers\Images@ID-1 AYAFA8BUg/E0gouOpBhoYjAArADMdmBAvMkOcBAAAAAAAAAAAAAAAAAAAAAAAAgUAEDAAAAAAkZQsPGMAcVauR2b3NHA8AACAQAAv7r76UoGZGE7jpCAAAgIOAAAAAQAAAAAAAAAAAAAAAAAAAAAXBQaA4GAkBwbAcHAzBAAAYBAGBQMAAAAAAw9ARTVwAwVlJGA0AACAQAAv7r76goGurDFsoCAAAwPfAAAAAQAAAAAAAAAAAAAAAAAAAAAXBQZAIGAAAgEAgFAxAAAAAAA4D0KbADAXFETMBVQ+FDAAAEAIAABA8uvurDFsgPQrshKAAAAA9BAAAAABAAAAAAAAAAAAAAAAAAAAcFAhBAbAwGAwBQYAAHAlBgcAAAAYAQ4EEDAAAAAAgPQrsBMAwUZu9mdv9VMAAgPAgAAEAw7+iPQrsB+AtyGqAAAAQ0HAAAAAEAAAAAAAAAAAAAAAAAAAAATAUGAuBwbAYHAvBwXAEDAAAAGAsIBAAAEA8uvBAAAAkHBAAQdEAAAxMFUTVQ1NXNnusBETeJCAsCL57aIAAAAQAAAAAwSAUGA5BgOAAFAJBARAAAATAAAAQGAAAQeDAAAUAAAAAwQA8GAuBAZAkGA0BQaA8GAuBAAAIEAAAgHAAAAwBgcA8GAwBANAIDA5AANAkDA2AwNAIDA5AQNAAAAAAwLDAAAT04bR4BEl+EhU/vg5hTG1AAAAAQAAAAALAAAAkIXxL1FaFOS72sRjiPn8JMAAAAAgr1zBp19GgUvHm1xZTij5SGAAAwCAAAAfAgBAAAAqAgLAoGAwBwZAAAAAAQAAAAAAAAAJyV8SdhWhj0uNb0o4zJfCDAAAAA4a9cQadvBI17hZdc2k4YukBAAAsAAAAwHAcAAAAgKA4CAqBAcAUGAnBAAAAAABAAAAAAAAkIXxL1FaFOS72sRjiPn8JMAAAAAgr1zBp19GgUvHm1xZTij5SGAAAwCAAAAfAgBAAAAqAgLAIGAtBAcAAAAAAQAAAAAAAAAJyV8Sdh Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpapers\Images@ID-2 AYAFA8BUg/E0gouOpBhoYjAArADMdmBAvMkOcBAAAAAAAAAAAAAAAAAAAAAAAAgUAEDAAAAAAkZQsPGMAcVauR2b3NHA8AACAQAAv7r76UoGZGE7jpCAAAgIOAAAAAQAAAAAAAAAAAAAAAAAAAAAXBQaA4GAkBwbAcHAzBAAAYBAGBQMAAAAAAw9ARTVwAwVlJGA0AACAQAAv7r76goGurDFsoCAAAwPfAAAAAQAAAAAAAAAAAAAAAAAAAAAXBQZAIGAAAgEAgFAxAAAAAAA4D0KbADAXFETMBVQ+FDAAAEAIAABA8uvurDFsgPQrshKAAAAA9BAAAAABAAAAAAAAAAAAAAAAAAAAcFAhBAbAwGAwBQYAAHAlBgcAAAAYAQ4EEDAAAAAAgPQrsBMAwUZu9mdv9VMAAgPAgAAEAw7+iPQrsB+AtyGqAAAAQ0HAAAAAEAAAAAAAAAAAAAAAAAAAAATAUGAuBwbAYHAvBwXAEDAAAAGAsIBAAAEA8uvBAAAAkHBAAQdEAAAxMFUTVQ1NXNnusBETeJCAsCL57aIAAAAQAAAAAwSAUGA5BgOAAFAJBARAAAATAAAAQGAAAQeDAAAUAAAAAwQA8GAuBAZAkGA0BQaA8GAuBAAAIEAAAgHAAAAwBgcA8GAwBANAIDA5AANAkDA2AwNAIDA5AQNAAAAAAwLDAAAT04bR4BEl+EhU/vg5hTG1AAAAAQAAAAALAAAAkIXxL1FaFOS72sRjiPn8JMAAAAAgr1zBp19GgUvHm1xZTij5SGAAAwCAAAAfAgBAAAAqAgLAoGAwBwZAAAAAAQAAAAAAAAAJyV8SdhWhj0uNb0o4zJfCDAAAAA4a9cQadvBI17hZdc2k4YukBAAAsAAAAwHAcAAAAgKA4CAqBAcAUGAnBAAAAAABAAAAAAAAkIXxL1FaFOS72sRjiPn8JMAAAAAgr1zBp19GgUvHm1xZTij5SGAAAwCAAAAfAgBAAAAqAgLAIGAtBAcAAAAAAQAAAAAAAAAJyV8Sdh Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy\GroupMembership@Count 11 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings@EmailName User@ Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings@SecureProtocols 160 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache@Signature Client UrlCache MMF Ver 5.2 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies@CacheLimit 8192 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld@CachePath %APPDATA%\Microsoft\Windows\IETldCache Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld@CachePrefix ietld: Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld@CacheLimit 8192 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld@CacheOptions 9 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld@CacheRepair 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History@CacheLimit 8192 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0@DisplayName Computer Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0@Description Your computer Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1@Flags 323 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap@UNCAsIntranet 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap@AutoDetect 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1@DisplayName Local intranet Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1@Description This zone contains all Web sites that are on your organization's intranet. Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1@Flags 323 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@DisplayName Trusted sites Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@Description This zone contains Web sites that you trust not to damage your computer or data. Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@2708 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@2709 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@Description This zone contains all Web sites you haven't placed in other zones Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2402 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2708 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@2709 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4@DisplayName Restricted sites Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4@Description This zone contains Web sites that could potentially damage your computer or data. Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@top 112 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@left 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@width 800 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@height 450 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@showCmd 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\MCE.PerUserSettings@SqmHasBattery Uninitialized Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Media Center\Settings\VideoSettings@SuppressVideoError 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@McAfee McItInfo C:\Users\Ewa\AppData\Local\Temp\mcitinfo_1397313172.exe /itinsfin:C:\Users\Ewa\AppData\Local\Temp\mcininfo_1397313172.ini Reg HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce@osk.exe osk.exe Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Themes@LastHighContrastTheme %SystemRoot%\resources\Ease of Access Themes\hcblack.theme Reg HKCU\Software\Microsoft\Windows\DWM@CompositionPolicy 0 Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting@LastQueuePesterTime 0x57 0xDC 0x77 0xB2 ... Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows@Device Microsoft XPS Document Writer,winspool,Ne00: Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows@UserSelectedDefault 0 ---- Files - GMER 2.2 ---- File C:\$RECYCLE.BIN\S-1-5-21-3631931409-1417981497-3388749590-1001\$RXNJ8JW 0 bytes File C:\Program Files\Common Files\Intel 0 bytes File C:\Program Files\Common Files\Intel\Media SDK 0 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1 0 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0 0 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\c.cpa 1505280 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\cpa.vp 993 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\dev.vp 44165 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\he_64.vp 2781 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\h_64.vp 2629 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\libmfxhw64-s1.dll 14547384 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_h264vd_64.dll 278528 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_h264ve_64.dll 303616 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_mp2vd_64.dll 278528 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_vc1vd_64.dll 278016 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_vpp_64.dll 287744 bytes executable File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\m_64.vp 2624 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\v1_64.vp 2628 bytes File C:\Program Files\Common Files\Intel\Media SDK\s1\2.0\vp_64.vp 2690 bytes File C:\Program Files\Lenovo\Customer Feedback Program 0 bytes File C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe 13112 bytes executable File C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll 12088 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\OpenPerfomanceTaskManager.exe 6144 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\battery\64\LenovoEmExpandedAPI.dll (size mismatch) 10240/16320 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Business.dll (size mismatch) 217088/626720 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\CriaPerfMonMemory.bat 145 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32\diag_memory.dll 1178688 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\32\ldiag_memory_x86.exe 416768 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64\diag_memory.dll 521280 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\64\ldiag_memory_x64.exe 491008 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\flex_comm_sample.exe 29184 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_memory_simulation.exe 28672 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_storage_x64.exe 221496 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_storage_x86.exe 187704 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\diag\ldiag_test.exe 166912 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Entity.dll (size mismatch) 4608/112064 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\EventViewer.dll 4608 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\fp_smbios.exe (size mismatch) 17920/120256 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.NetFwTypeLib.dll (size mismatch) 19456/26048 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.PlaLibrary.dll (size mismatch) 73728/79808 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Interop.TaskScheduler.dll (size mismatch) 49152/55232 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\KillProcessLSC.exe (size mismatch) 5120/12224 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Lenovo.TVT.Core.Logging.dll 23352 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCController.dll (size mismatch) 49664/86568 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe (size mismatch) 7680/269856 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.vshost.exe 14328 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.vshost.exe.manifest 490 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService32.exe 7680 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService32.vshost.exe 14328 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\MemoryMonitor.exe 5120 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\PerformanceMonitor.dll 12288 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\ProcessorMonitor.exe 5120 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.exe 12600 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.vshost.exe 11064 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\RunAsAdministrator.vshost.exe.manifest 1247 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\App\TaskScheduler.dll (size mismatch) 14336/20416 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\Util.dll (size mismatch) 7168/60864 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\WindowsRegistry.dll (size mismatch) 6144/12736 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\App\WindowWrapper.dll 7168 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesBasic.xml 456 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesBasicResult.xml 705 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\DiagSuitesComprehensive.xml 499 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\configHistory1.jpg 108114 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\overViewTop.jpg 31813 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\114x114.png 15637 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\128x128.png 17054 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\16x16.png 3574 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\256x256.png 27977 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\32x32.png 5081 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\36x36.png 5498 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\48x48.png 6893 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\72x72.png 9838 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\accessOnline1.jpg 117796 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\antiVirus1.jpg 111070 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\backup1.jpg 130860 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\battery1.jpg 108576 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\checkupIcon.png 8660 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\configHistory.jpg 101789 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\configHistory.png 9536 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\configHistory2.jpg 98008 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\CPU.png 10859 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\deviceManager1.jpg 116970 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\DeviceManagerIcon.png 9905 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\filePrinter.jpg 95618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\fileprinterIcon.png 6965 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\fingerprint1.jpg 96424 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\fingerprintIcon.png 12057 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\firewall1.jpg 102201 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\firewallIcon.png 9907 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\gettingStarted.jpg 140036 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\gettingStarted2.jpg 125985 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\HDIcon.png 8465 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan1.jpg 103039 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan2.jpg 102229 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan3.jpg 114788 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan4.jpg 115396 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\hwScan5.jpg 136972 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnAlertCritical.png 5135 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnAlertNonCritical.png 4618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnAlert_16x16.png 3141 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnError_16x16.png 3366 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnIgnored_16x16.png 3375 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\icnOk_16x16.png 3497 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\internetConnection.png 13657 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\internetConnection1.jpg 91212 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\memory1.jpg 134069 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\memoryIcon.png 11560 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\onlinesupportIcon.png 10603 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\password1.jpg 93738 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\passwordIcon.png 7468 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\recoveryMedia.png 11272 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\software1.jpg 133940 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\storage1.jpg 132749 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\supportModule_WarrantyIcon.png 13970 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\sysInfo.png 9980 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\systemInfo1.jpg 132056 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\systemModule_backupIcon.png 8780 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\systemModule_batteryIcon.png 8006 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\updateIcon.png 11659 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\virusblue.png 13944 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\warranty1.jpg 122570 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\images\wireless.png 8286 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\Lenovo Solution Center Help.exe 142848 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SupportConfigHistoryCalendar.html 1575 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupDeviceManager.html 3482 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanCustTests.html 1502 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanDefTests.html 1534 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanFirstView.html 3821 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanTestRun.html 2075 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\CheckupHardwareScanViewLog.html 1296 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\GettingStartedAlertsView.html 3621 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\GettingStartedFunctionalityView.html 1496 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\HomeAlertsView.html 1246 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\HomeDashboardView.html 4364 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SecurityFingerprint.html 1253 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SecurityFirewall.html 3632 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SecurityInternetConnection.html 1714 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SecurityPassword.html 1308 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SecurityVirusProtection.html 4235 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SupportAccessOnline.html 1506 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SupportConfigHistorySelectedDate.html 2108 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SupportWarranty.html 3678 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemBackup.html 4953 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemBattery.html 3980 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemFileAndPrinter.html 1799 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemMemory.html 4778 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemSoftwareUpdates.html 4403 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemStorageDevices.html 4223 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\SystemSystemInformation.html 2375 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\da_DK\Welcome.html 845 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SupportConfigHistoryCalendar.html 1725 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupDeviceManager.html 3707 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanCustTests.html 1648 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanDefTests.html 1711 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanFirstView.html 4013 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanTestRun.html 2415 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\CheckupHardwareScanViewLog.html 1489 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\GettingStartedAlertsView.html 4213 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\GettingStartedFunctionalityView.html 1555 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\HomeAlertsView.html 1336 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\HomeDashboardView.html 4540 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SecurityFingerprint.html 1328 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SecurityFirewall.html 3889 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SecurityInternetConnection.html 1846 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SecurityPassword.html 1391 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SecurityVirusProtection.html 4532 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SupportAccessOnline.html 1585 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SupportConfigHistorySelectedDate.html 2275 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SupportWarranty.html 4049 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemBackup.html 5086 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemBattery.html 4334 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemFileAndPrinter.html 2040 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemMemory.html 5180 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemSoftwareUpdates.html 4790 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemStorageDevices.html 4649 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\SystemSystemInformation.html 2552 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\de_DE\Welcome.html 876 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\GettingStartedFunctionalityView.html 1437 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupDeviceManager.html 3335 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScan.html 3311 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanCustTests.html 1485 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanDefTests.html 1520 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanFirstView.html 3608 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanTestRun.html 2106 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\CheckupHardwareScanViewLog.html 1311 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\GettingStartedAlertsView.html 3497 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\GettingStartedPrincipalView.html 3369 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\HomeAlertsView.html 1209 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\HomeDashboardView.html 4187 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SecurityFingerprint.html 1240 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SecurityFirewall.html 3490 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SecurityInternetConnection.html 1647 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SecurityPassword.html 1275 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SecurityVirusProtection.html 4067 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SupportAccessOnline.html 1411 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SupportConfigHistoryCalendar.html 1493 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SupportConfigHistorySelectedDate.html 2004 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SupportWarranty.html 3640 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemBackup.html 4462 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemBattery.html 3825 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemFileAndPrinter.html 1774 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemMemory.html 4574 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemSoftwareUpdates.html 4173 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemStorageDevices.html 4059 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\SystemSystemInformation.html 2380 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\en_US\Welcome.html 974 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SupportConfigHistoryCalendar.html 1577 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupDeviceManager.html 3587 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanCustTests.html 1635 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanDefTests.html 1703 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanFirstView.html 3895 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanTestRun.html 2263 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\CheckupHardwareScanViewLog.html 1412 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\GettingStartedAlertsView.html 3808 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\GettingStartedFunctionalityView.html 1512 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\HomeAlertsView.html 1266 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\HomeDashboardView.html 4437 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SecurityFingerprint.html 1296 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SecurityFirewall.html 3670 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SecurityInternetConnection.html 1666 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SecurityPassword.html 1376 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SecurityVirusProtection.html 4253 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SupportAccessOnline.html 1495 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SupportConfigHistorySelectedDate.html 2137 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SupportWarranty.html 3834 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemBackup.html 4999 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemBattery.html 4020 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemFileAndPrinter.html 1914 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemMemory.html 4751 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemSoftwareUpdates.html 4519 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemStorageDevices.html 4368 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\SystemSystemInformation.html 2480 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\es_ES\Welcome.html 877 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SupportConfigHistoryCalendar.html 1685 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupDeviceManager.html 3506 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanCustTests.html 1542 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanDefTests.html 1603 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanFirstView.html 3841 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanTestRun.html 2166 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\CheckupHardwareScanViewLog.html 1354 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\GettingStartedAlertsView.html 3697 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\GettingStartedFunctionalityView.html 1498 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\HomeAlertsView.html 1295 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\HomeDashboardView.html 4293 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SecurityFingerprint.html 1233 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SecurityFirewall.html 3685 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SecurityInternetConnection.html 1708 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SecurityPassword.html 1302 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SecurityVirusProtection.html 4267 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SupportAccessOnline.html 1459 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SupportConfigHistorySelectedDate.html 2089 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SupportWarranty.html 3743 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemBackup.html 4773 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemBattery.html 3978 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemFileAndPrinter.html 1863 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemMemory.html 4718 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemSoftwareUpdates.html 4389 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemStorageDevices.html 4232 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\SystemSystemInformation.html 2476 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fi_FI\Welcome.html 862 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SupportConfigHistoryCalendar.html 1647 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupDeviceManager.html 3657 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanCustTests.html 1646 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanDefTests.html 1734 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanFirstView.html 4053 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanTestRun.html 2236 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\CheckupHardwareScanViewLog.html 1433 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\GettingStartedAlertsView.html 4001 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\GettingStartedFunctionalityView.html 1530 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\HomeAlertsView.html 1326 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\HomeDashboardView.html 4491 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SecurityFingerprint.html 1326 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SecurityFirewall.html 3690 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SecurityInternetConnection.html 1746 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SecurityPassword.html 1375 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SecurityVirusProtection.html 4332 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SupportAccessOnline.html 1555 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SupportConfigHistorySelectedDate.html 2232 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SupportWarranty.html 3932 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemBackup.html 4971 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemBattery.html 4171 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemFileAndPrinter.html 1954 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemMemory.html 4989 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemSoftwareUpdates.html 4687 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemStorageDevices.html 4490 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\SystemSystemInformation.html 2558 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\fr_FR\Welcome.html 880 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SupportConfigHistoryCalendar.html 1641 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupDeviceManager.html 3645 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanCustTests.html 1659 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanDefTests.html 1735 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanFirstView.html 4012 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanTestRun.html 2319 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\CheckupHardwareScanViewLog.html 1440 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\GettingStartedAlertsView.html 3886 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\GettingStartedFunctionalityView.html 1592 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\HomeAlertsView.html 1312 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\HomeDashboardView.html 4450 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SecurityFingerprint.html 1338 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SecurityFirewall.html 3701 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SecurityInternetConnection.html 1709 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SecurityPassword.html 1358 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SecurityVirusProtection.html 4284 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SupportAccessOnline.html 1561 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SupportConfigHistorySelectedDate.html 2216 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SupportWarranty.html 3883 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemBackup.html 4920 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemBattery.html 4218 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemFileAndPrinter.html 1973 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemMemory.html 4995 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemSoftwareUpdates.html 4640 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemStorageDevices.html 4514 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\SystemSystemInformation.html 2548 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\it_IT\Welcome.html 872 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SupportConfigHistoryCalendar.html 1723 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupDeviceManager.html 4087 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanCustTests.html 1768 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanDefTests.html 1909 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanFirstView.html 4422 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanTestRun.html 2478 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\CheckupHardwareScanViewLog.html 1514 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\GettingStartedAlertsView.html 4564 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\GettingStartedFunctionalityView.html 1618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\HomeAlertsView.html 1355 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\HomeDashboardView.html 4827 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SecurityFingerprint.html 1379 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SecurityFirewall.html 4413 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SecurityInternetConnection.html 2017 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SecurityPassword.html 1532 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SecurityVirusProtection.html 5082 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SupportAccessOnline.html 1798 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SupportConfigHistorySelectedDate.html 2453 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SupportWarranty.html 4238 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemBackup.html 5631 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemBattery.html 4591 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemFileAndPrinter.html 2135 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemMemory.html 5697 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemSoftwareUpdates.html 5195 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemStorageDevices.html 4986 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\SystemSystemInformation.html 2892 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ja_JP\Welcome.html 939 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SupportConfigHistoryCalendar.html 1625 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupDeviceManager.html 3622 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanCustTests.html 1573 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanDefTests.html 1685 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanFirstView.html 3985 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanTestRun.html 2266 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\CheckupHardwareScanViewLog.html 1395 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\GettingStartedAlertsView.html 3821 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\GettingStartedFunctionalityView.html 1533 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\HomeAlertsView.html 1300 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\HomeDashboardView.html 4682 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SecurityFingerprint.html 1298 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SecurityFirewall.html 3853 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SecurityInternetConnection.html 1724 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SecurityPassword.html 1297 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SecurityVirusProtection.html 4537 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SupportAccessOnline.html 1610 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SupportConfigHistorySelectedDate.html 2100 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SupportWarranty.html 3846 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemBackup.html 4971 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemBattery.html 4230 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemFileAndPrinter.html 1924 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemMemory.html 5012 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemSoftwareUpdates.html 4771 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemStorageDevices.html 4431 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\SystemSystemInformation.html 2457 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ko_KR\Welcome.html 909 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SupportConfigHistoryCalendar.html 1533 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupDeviceManager.html 3433 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanCustTests.html 1518 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanDefTests.html 1553 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanFirstView.html 3747 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanTestRun.html 2099 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\CheckupHardwareScanViewLog.html 1296 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\GettingStartedAlertsView.html 3578 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\GettingStartedFunctionalityView.html 1476 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\HomeAlertsView.html 1214 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\HomeDashboardView.html 4290 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SecurityFingerprint.html 1268 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SecurityFirewall.html 3575 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SecurityInternetConnection.html 1645 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SecurityPassword.html 1307 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SecurityVirusProtection.html 4139 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SupportAccessOnline.html 1530 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SupportConfigHistorySelectedDate.html 2063 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SupportWarranty.html 3647 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemBackup.html 4810 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemBattery.html 3941 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemFileAndPrinter.html 1783 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemMemory.html 4579 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemSoftwareUpdates.html 4425 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemStorageDevices.html 4157 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\SystemSystemInformation.html 2358 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nb_NO\Welcome.html 845 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SupportConfigHistoryCalendar.html 1604 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupDeviceManager.html 3654 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanCustTests.html 1585 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanDefTests.html 1597 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanFirstView.html 3932 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanTestRun.html 2288 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\CheckupHardwareScanViewLog.html 1419 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\GettingStartedAlertsView.html 3753 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\GettingStartedFunctionalityView.html 1615 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\HomeAlertsView.html 1377 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\HomeDashboardView.html 4411 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SecurityFingerprint.html 1307 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SecurityFirewall.html 3789 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SecurityInternetConnection.html 1778 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SecurityPassword.html 1358 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SecurityVirusProtection.html 4370 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SupportAccessOnline.html 1574 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SupportConfigHistorySelectedDate.html 2240 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SupportWarranty.html 3839 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemBackup.html 4909 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemBattery.html 4107 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemFileAndPrinter.html 1924 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemMemory.html 5021 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemSoftwareUpdates.html 4520 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemStorageDevices.html 4454 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\SystemSystemInformation.html 2505 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\nl_NL\Welcome.html 869 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SupportConfigHistoryCalendar.html 1671 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupDeviceManager.html 3622 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanCustTests.html 1634 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanDefTests.html 1678 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanFirstView.html 3960 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanTestRun.html 2230 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\CheckupHardwareScanViewLog.html 1426 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\GettingStartedAlertsView.html 3879 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\GettingStartedFunctionalityView.html 1522 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\HomeAlertsView.html 1250 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\HomeDashboardView.html 4469 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SecurityFingerprint.html 1326 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SecurityFirewall.html 3750 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SecurityInternetConnection.html 1822 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SecurityPassword.html 1307 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SecurityVirusProtection.html 4463 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SupportAccessOnline.html 1600 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SupportConfigHistorySelectedDate.html 2137 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SupportWarranty.html 3852 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemBackup.html 5038 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemBattery.html 4144 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemFileAndPrinter.html 1951 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemMemory.html 5051 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemSoftwareUpdates.html 4576 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemStorageDevices.html 4497 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\SystemSystemInformation.html 2544 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pl_PL\Welcome.html 865 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SupportConfigHistoryCalendar.html 1565 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupDeviceManager.html 3488 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanCustTests.html 1580 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanDefTests.html 1677 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanFirstView.html 3902 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanTestRun.html 2249 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\CheckupHardwareScanViewLog.html 1377 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\GettingStartedAlertsView.html 3807 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\GettingStartedFunctionalityView.html 1504 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\HomeAlertsView.html 1259 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\HomeDashboardView.html 4341 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SecurityFingerprint.html 1316 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SecurityFirewall.html 3618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SecurityInternetConnection.html 1693 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SecurityPassword.html 1321 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SecurityVirusProtection.html 4266 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SupportAccessOnline.html 1515 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SupportConfigHistorySelectedDate.html 2159 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SupportWarranty.html 3782 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemBackup.html 4711 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemBattery.html 3997 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemFileAndPrinter.html 1898 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemMemory.html 4788 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemSoftwareUpdates.html 4494 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemStorageDevices.html 4294 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\SystemSystemInformation.html 2508 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_BR\Welcome.html 853 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SupportConfigHistoryCalendar.html 1558 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupDeviceManager.html 3573 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanCustTests.html 1633 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanDefTests.html 1674 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanFirstView.html 3906 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanTestRun.html 2268 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\CheckupHardwareScanViewLog.html 1464 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\GettingStartedAlertsView.html 3869 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\GettingStartedFunctionalityView.html 1530 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\HomeAlertsView.html 1277 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\HomeDashboardView.html 4443 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SecurityFingerprint.html 1324 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SecurityFirewall.html 3691 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SecurityInternetConnection.html 1680 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SecurityPassword.html 1378 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SecurityVirusProtection.html 4271 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SupportAccessOnline.html 1539 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SupportConfigHistorySelectedDate.html 2152 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SupportWarranty.html 3815 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemBackup.html 5056 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemBattery.html 4043 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemFileAndPrinter.html 1892 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemMemory.html 4857 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemSoftwareUpdates.html 4529 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemStorageDevices.html 4381 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\SystemSystemInformation.html 2510 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\pt_PT\Welcome.html 866 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SupportConfigHistoryCalendar.html 2195 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupDeviceManager.html 4688 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanCustTests.html 2132 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanDefTests.html 2327 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanFirstView.html 5302 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanTestRun.html 2801 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\CheckupHardwareScanViewLog.html 1819 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\GettingStartedAlertsView.html 5820 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\GettingStartedFunctionalityView.html 2231 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\HomeAlertsView.html 1618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\HomeDashboardView.html 5854 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SecurityFingerprint.html 1727 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SecurityFirewall.html 4931 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SecurityInternetConnection.html 2385 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SecurityPassword.html 1759 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SecurityVirusProtection.html 5969 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SupportAccessOnline.html 2249 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SupportConfigHistorySelectedDate.html 2969 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SupportWarranty.html 5077 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemBackup.html 7117 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemBattery.html 5696 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemFileAndPrinter.html 2505 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemMemory.html 6773 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemSoftwareUpdates.html 6199 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemStorageDevices.html 5919 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\SystemSystemInformation.html 3404 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\ru_RU\Welcome.html 1257 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SupportConfigHistoryCalendar.html 1566 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupDeviceManager.html 3440 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanCustTests.html 1559 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanDefTests.html 1527 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanFirstView.html 3813 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanTestRun.html 2093 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\CheckupHardwareScanViewLog.html 1336 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\GettingStartedAlertsView.html 3547 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\GettingStartedFunctionalityView.html 1497 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\HomeAlertsView.html 1228 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\HomeDashboardView.html 4335 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SecurityFingerprint.html 1289 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SecurityFirewall.html 3627 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SecurityInternetConnection.html 1680 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SecurityPassword.html 1318 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SecurityVirusProtection.html 4105 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SupportAccessOnline.html 1432 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SupportConfigHistorySelectedDate.html 2073 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SupportWarranty.html 3629 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemBackup.html 4766 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemBattery.html 3906 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemFileAndPrinter.html 1827 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemMemory.html 4707 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemSoftwareUpdates.html 4406 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemStorageDevices.html 4162 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\SystemSystemInformation.html 2374 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\sv_SE\Welcome.html 846 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SupportConfigHistoryCalendar.html 1366 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupDeviceManager.html 3200 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanCustTests.html 1360 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanDefTests.html 1387 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanFirstView.html 3456 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanTestRun.html 1923 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\CheckupHardwareScanViewLog.html 1227 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\GettingStartedAlertsView.html 3246 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\GettingStartedFunctionalityView.html 1318 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\HomeAlertsView.html 1196 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\HomeDashboardView.html 3983 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SecurityFingerprint.html 1142 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SecurityFirewall.html 3338 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SecurityInternetConnection.html 1535 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SecurityPassword.html 1149 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SecurityVirusProtection.html 3814 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SupportAccessOnline.html 1309 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SupportConfigHistorySelectedDate.html 1771 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SupportWarranty.html 3439 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemBackup.html 4212 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemBattery.html 3647 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemFileAndPrinter.html 1731 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemMemory.html 4288 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemSoftwareUpdates.html 3957 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemStorageDevices.html 3832 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\SystemSystemInformation.html 2148 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_CN\Welcome.html 786 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SupportConfigHistoryCalendar.html 1412 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupDeviceManager.html 3244 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanCustTests.html 1390 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanDefTests.html 1435 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanFirstView.html 3495 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanTestRun.html 1962 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\CheckupHardwareScanViewLog.html 1239 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\GettingStartedAlertsView.html 3290 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\GettingStartedFunctionalityView.html 1348 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\HomeAlertsView.html 1187 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\HomeDashboardView.html 4064 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SecurityFingerprint.html 1159 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SecurityFirewall.html 3368 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SecurityInternetConnection.html 1595 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SecurityPassword.html 1185 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SecurityVirusProtection.html 3844 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SupportAccessOnline.html 1364 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SupportConfigHistorySelectedDate.html 1835 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SupportWarranty.html 3467 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemBackup.html 4276 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemBattery.html 3643 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemFileAndPrinter.html 1759 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemMemory.html 4395 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemSoftwareUpdates.html 4026 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemStorageDevices.html 3903 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\SystemSystemInformation.html 2232 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_HK\Welcome.html 798 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SupportConfigHistoryCalendar.html 1412 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupDeviceManager.html 3244 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanCustTests.html 1390 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanDefTests.html 1435 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanFirstView.html 3495 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanTestRun.html 1962 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\CheckupHardwareScanViewLog.html 1239 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\GettingStartedAlertsView.html 3290 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\GettingStartedFunctionalityView.html 1348 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\HomeAlertsView.html 1187 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\HomeDashboardView.html 4064 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SecurityFingerprint.html 1159 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SecurityFirewall.html 3368 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SecurityInternetConnection.html 1595 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SecurityPassword.html 1185 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SecurityVirusProtection.html 3844 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SupportAccessOnline.html 1364 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SupportConfigHistorySelectedDate.html 1835 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SupportWarranty.html 3467 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemBackup.html 4276 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemBattery.html 3643 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemFileAndPrinter.html 1759 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemMemory.html 4395 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemSoftwareUpdates.html 4026 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemStorageDevices.html 3903 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\SystemSystemInformation.html 2232 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\locale\zh_TW\Welcome.html 798 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\Main.swf 549139 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\menu.xml 2182 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\META-INF 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\META-INF\AIR 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\META-INF\AIR\application.xml 9139 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\META-INF\AIR\hash 32 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\META-INF\signatures.xml 132635 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\mimetype 59 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\style 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\help\style\HelpStyle.css 1601 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\Licenses\Readme.txt 28814 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe (size mismatch) 148280/148416 bytes executable File C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe.manifest 908 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\btnSettingsDisabled.png 3618 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\icnFilePrinter.png 2994 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusgray.png 10100 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusgreen.png 11157 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusred.png 11461 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\defaultSkin\images\virusyellow.png 9941 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\silverSkin 0 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\skins\silverSkin\style.css 3327 bytes File C:\Program Files\Lenovo\Lenovo Solution Center\[Content_Types].xml 919 bytes File C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcpluir.dll (size mismatch) 4464960/10319928 bytes executable File C:\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll (size mismatch) 4096/20536 bytes executable File C:\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll (size mismatch) 261120/184816 bytes executable File C:\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll (size mismatch) 202752/126088 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvdisps.dll (size mismatch) 9931072/10488768 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvdispsr.dll (size mismatch) 10360128/10809400 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvgames.dll (size mismatch) 7968576/11267008 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvgamesr.dll (size mismatch) 8051520/11399224 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvmccss.dll (size mismatch) 222016/303552 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvmccssr.dll (size mismatch) 458560/465976 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvmobls.dll (size mismatch) 3628352/3803192 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvmoblsr.dll (size mismatch) 2854720/2859456 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvsmartmax.dll (size mismatch) 78144/121280 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvsmartmax64.dll (size mismatch) 84288/134712 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvsmartmaxapp.exe (size mismatch) 49472/70712 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvsmartmaxapp64.exe (size mismatch) 49472/70712 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvsvsr.dll (size mismatch) 1876800/1929152 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (size mismatch) 2448704/2456632 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvui.dll (size mismatch) 4119360/5119544 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvuir.dll (size mismatch) 1196352/1892800 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvvitvsr.dll (size mismatch) 4107584/4108344 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvwss.dll (size mismatch) 10251072/11186112 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvwssr.dll (size mismatch) 7981888/9230392 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll (size mismatch) 5272384/6661056 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll (size mismatch) 1221440/1348664 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll (size mismatch) 1512768/1630144 bytes executable File C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (size mismatch) 1114944/1263160 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E} 0 bytes File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVI2.dll 4579016 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVI2SystemService32.sys 13512 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVI2SystemService64.sys 15688 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVI2UI.dll 1446216 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVPrxy32.dll 891592 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\NVPrxy64.dll 1571656 bytes File C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{DF8027F8-9A51-4564-AE9A-A5C1F625268E}\setup.exe 412872 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0 0 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0000.ui.forms 44832 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0000.ui.strings 474 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0401.ui.forms 2368 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0401.ui.strings 8986 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0404.ui.forms 2541 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0404.ui.strings 7122 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0405.ui.forms 2821 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0405.ui.strings 7714 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0406.ui.forms 2616 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3.chm 71919 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ARA.chm 75612 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3CHS.chm 76346 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3CHT.chm 77298 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3CSY.chm 77604 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3DAN.chm 71799 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3DEU.chm 75258 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ELL.chm 77847 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ENG.chm 72138 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ESM.chm 73044 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ESN.chm 73168 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3FIN.chm 76309 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3FRA.chm 73838 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0407.ui.forms 3695 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0407.ui.strings 8254 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0408.ui.forms 4573 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0408.ui.strings 11175 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0409.ui.forms 2458 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0409.ui.strings 7436 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040a.ui.forms 3441 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040a.ui.strings 7767 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040b.ui.forms 3103 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040b.ui.strings 7654 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040c.ui.forms 4018 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040c.ui.strings 8086 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040d.ui.forms 2557 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040d.ui.strings 9132 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040e.ui.forms 2770 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\040e.ui.strings 7880 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0410.ui.forms 2739 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0411.ui.forms 2614 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0411.ui.strings 8942 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0412.ui.forms 2602 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0412.ui.strings 7970 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0413.ui.forms 3732 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0413.ui.strings 7867 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0414.ui.forms 2805 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0414.ui.strings 7581 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0406.ui.strings 7551 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0410.ui.strings 7964 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041d.ui.strings 7543 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_disable_90.png 705 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_135.png 815 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\DisplayControlPanel.nvi 62346 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dCHS.chm 160697 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dPTG.chm 155954 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplESM.chm 136258 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplTHA.chm 144915 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspHEB.chm 221193 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvhotkey.dll 446784 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobHEB.chm 50991 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvSmartMaxapp64.exe 49472 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3HEB.chm 77992 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvsvsr.dll 1876800 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksFRA.chm 883828 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwssr.dll 7981888 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0415.ui.forms 4109 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0415.ui.strings 7779 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0416.ui.forms 3642 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0416.ui.strings 7648 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0419.ui.forms 3167 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0419.ui.strings 9923 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041b.ui.forms 2765 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041b.ui.strings 7828 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041d.ui.forms 2368 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041e.ui.forms 3640 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041e.ui.strings 12787 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041f.ui.forms 2912 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\041f.ui.strings 7573 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0424.ui.forms 3004 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0424.ui.strings 7717 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0804.ui.strings 6921 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0809.ui.strings 7275 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\080a.ui.strings 7778 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0816.ui.forms 3555 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\0816.ui.strings 7898 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\box_checked_disabled.png 937 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\box_checked_enabled.png 821 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\box_unchecked_disabled.png 180 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\box_unchecked_enabled.png 701 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_disable_135.png 720 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_disable_180.png 738 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_135.png 870 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_180.png 894 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_90.png 852 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_focus_135.png 882 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_focus_180.png 908 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_focus_90.png 863 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_pressed_135.png 842 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_pressed_180.png 867 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_primary_pressed_90.png 822 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_180.png 833 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_90.png 796 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_focus_135.png 801 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_focus_180.png 824 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_focus_90.png 789 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_pressed_135.png 819 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_pressed_180.png 841 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\btn_secondary_pressed_90.png 803 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\check.png 731 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\checkmark.png 641 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\DisplayControlPanel.NVX 44713 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\DisplayCplExt.dll 990016 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\error.png 2531 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\info.png 2191 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\install_bg.png 62032 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\install_bg_rtl.png 60088 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3d.chm 140603 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\Nv3DAppShExt.dll 850752 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\Nv3DAppShExtR.dll 55616 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dARA.chm 159148 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dCHT.chm 164021 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dCSY.chm 183398 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dDAN.chm 166460 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dDEU.chm 174896 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dELL.chm 168164 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dENG.chm 156141 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dESM.chm 150400 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dESN.chm 149111 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dFIN.chm 159240 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dFRA.chm 152865 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dHEB.chm 170436 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dHUN.chm 172916 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dITA.chm 152609 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dJPN.chm 185523 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dKOR.chm 162917 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dNLD.chm 147423 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dNOR.chm 146602 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dPLK.chm 166543 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dPTB.chm 148498 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dRUS.chm 160194 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dSKY.chm 187045 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dSLV.chm 166751 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dSVE.chm 166926 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dTHA.chm 173177 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nv3dTRK.chm 159573 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcoproc.bin 2609389 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcpl.chm 130443 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcpl.cpl 417088 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NvCpl.dll 6103360 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplARA.chm 140272 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplCHS.chm 138797 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplCHT.chm 140711 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplCSY.chm 140240 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplDAN.chm 136259 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplDEU.chm 138570 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplELL.chm 142464 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplENG.chm 135526 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplESN.chm 136168 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplFIN.chm 139856 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplFRA.chm 136667 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplHEB.chm 143205 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplHUN.chm 142142 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplITA.chm 137662 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplJPN.chm 147166 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplKOR.chm 140257 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplNLD.chm 136316 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplNOR.chm 137438 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplPLK.chm 140967 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplPTB.chm 136092 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplPTG.chm 137564 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplRUS.chm 140728 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplSKY.chm 142743 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplSLV.chm 141490 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplSVE.chm 137907 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplTRK.chm 140739 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcplui.exe 6861120 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvcpluir.dll 4464960 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdisps.dll 9931072 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdispsr.dll 10360128 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdsp.chm 187943 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspARA.chm 210971 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspCHS.chm 209663 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspCHT.chm 220021 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspCSY.chm 215526 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspDAN.chm 197502 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspDEU.chm 200876 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspELL.chm 221350 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspENG.chm 192810 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspESM.chm 194507 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspESN.chm 194633 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspFIN.chm 206323 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspFRA.chm 196984 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspHUN.chm 220456 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspITA.chm 199770 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspJPN.chm 253187 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspKOR.chm 221587 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspNLD.chm 196508 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspNOR.chm 193199 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspPLK.chm 217222 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspPTB.chm 195360 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspPTG.chm 200536 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspRUS.chm 214416 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspSKY.chm 221284 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspSLV.chm 219665 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspSVE.chm 198548 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspTHA.chm 238784 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvdspTRK.chm 208272 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvgames.dll 7968576 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvgamesr.dll 8051520 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NVI2.dll 3191616 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NVI2UI.dll 1319232 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmccss.dll 222016 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmccssr.dll 458560 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NvMCTray.dll 118080 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmob.chm 51921 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobARA.chm 50525 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobCHS.chm 50600 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobCHT.chm 51372 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobCSY.chm 50556 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobDAN.chm 50003 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobDEU.chm 50750 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobELL.chm 51665 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobENG.chm 52094 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobESM.chm 50200 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobESN.chm 50176 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobFIN.chm 50753 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobFRA.chm 50648 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobHUN.chm 51055 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobITA.chm 50490 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobJPN.chm 51838 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobKOR.chm 50686 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobls.dll 3628352 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmoblsr.dll 2854720 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobNLD.chm 50748 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobNOR.chm 49804 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobPLK.chm 50825 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobPTB.chm 50376 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobPTG.chm 50348 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobRUS.chm 50585 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobSKY.chm 50627 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobSLV.chm 50823 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobSVE.chm 52845 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobTHA.chm 50831 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvmobTRK.chm 50665 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NVPrxy32.dll 775488 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NVPrxy64.dll 1249088 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvshext.dll 63296 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvSmartMax.dll 78144 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvSmartMax64.dll 84288 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvSmartMaxapp.exe 49472 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3HUN.chm 77538 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3ITA.chm 73779 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3JPN.chm 83992 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3KOR.chm 78098 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3NLD.chm 71371 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3NOR.chm 70461 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3PLK.chm 77787 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3PTB.chm 73064 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3PTG.chm 72909 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3RUS.chm 75813 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3SKY.chm 79431 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3SLV.chm 76545 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3SVE.chm 71043 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3THA.chm 79593 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvst3TRK.chm 75798 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvsvc64.dll 3092800 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvsvcr.dll 2561856 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvsvs.dll 3981632 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NVTray.exe 2448704 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\NvUI.dll 4119360 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvuir.dll 1196352 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvvitvs.dll 6405952 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvvitvsr.dll 4107584 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvvsvc.exe 889664 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwks.chm 900634 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksARA.chm 891478 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksCHS.chm 885174 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksCHT.chm 889942 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksCSY.chm 891938 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksDAN.chm 879744 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksDEU.chm 884197 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksELL.chm 894296 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksENG.chm 897699 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksESM.chm 879151 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksESN.chm 879315 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksFIN.chm 886188 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksHEB.chm 897440 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksHUN.chm 891698 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksITA.chm 880343 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksJPN.chm 909757 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksKOR.chm 892722 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksNLD.chm 875373 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksNOR.chm 884046 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksPLK.chm 892782 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksPTB.chm 878127 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksPTG.chm 885603 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksRUS.chm 889285 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksSKY.chm 894636 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksSLV.chm 891607 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksSVE.chm 880379 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksTHA.chm 900583 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwksTRK.chm 888364 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvwss.dll 10251072 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvxdapix.dll 5272384 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvxdbat.dll 1221440 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvxdplcy.dll 1512768 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\nvxdsync.exe 1114944 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\oemdspif.dll 427328 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\presentations_bg.png 143326 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\presentations_bg_rtl.png 140906 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\radio_btn_selected.png 1718 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\radio_btn_unselected.png 1516 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\setup.cfg 8733 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\Setup.exe 363840 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\splash.png 161250 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\splash_rtl.png 163624 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\theme.cfg 8830 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\uninstall_bg.png 64596 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\uninstall_bg_rtl.png 62297 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.0\warning.png 1601 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.PhysX.0 0 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.PhysX.0\PhysX.nvi 17867 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.PhysX.0\PhysX.NVX 2235 bytes File C:\Program Files\NVIDIA Corporation\Installer2\Display.PhysX.0\PhysXExt.dll 308544 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\Display.PhysX.0\PhysX_9.12.0213_SystemSoftware.msi 30412800 bytes File C:\Program Files\NVIDIA Corporation\Installer2\installer.1 0 bytes File C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.dll 3191616 bytes executable File C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVPrxy32.dll 775488 bytes File C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVPrxy64.dll 1249088 bytes File C:\Program Files\NVIDIA Corporation\Installer2\installer.1\setup.cfg 8733 bytes File C:\Program Files\NVIDIA Corporation\Installer2\installer.1\Setup.exe 363840 bytes executable File C:\Program Files\NVIDIA Corporation\Update Common 0 bytes File C:\Program Files\NVIDIA Corporation\Update Common\EasyDaemonAPIU64.dll 782656 bytes executable File C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll 3443520 bytes executable File C:\Program Files\NVIDIA Corporation\Update Common\NvUpdtr.dll 981824 bytes executable File C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstaller.exe (size mismatch) 53632/310960 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Esl 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Esl\AiodLite.dll 104344 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\adoberfp.dll 239512 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\cryptocme2.sig 1607 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Onix32.dll 759816 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\A3DUtils.dll 205720 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ACE.dll 818568 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe 296344 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Acrofx32.dll 63384 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.dll 24731544 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe 1480600 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32Info.exe 17824 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRdIF.dll 102808 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroTextExtractor.exe 49064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Adobe.Reader.Dependencies.manifest 1472 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe 1240992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeLinguistic.dll 757664 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeXMP.dll 304536 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AGM.dll 5509512 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AGMGPUOptIn.ini 1727 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ahclient.dll 225656 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll 183696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\authplay.dll 6543768 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AXE8SharedExpat.dll 174496 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AXSLE.dll 595344 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\BIB.dll 110472 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\BIBUtils.dll 154520 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll 183696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ccme_base.dll 1785856 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\CoolType.dll 2695064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\cryptocme2.dll 1839104 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Eula.exe 94608 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ExtendScript.dll 670624 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\icucnv40.dll 721832 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\icudt40.dll 96144 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\AdobeID.pdf 82070 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\DefaultID.pdf 80651 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\AdobeID.pdf 158882 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\DefaultID.pdf 154954 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts\JSByteCodeWin.bin 1189004 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\JP2KLib.dll 686464 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\eula.ini 1040 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\license.html 43061 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\eula.ini 1136 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\license.html 61600 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\accessibility.POL 44032 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Acroform.POL 427520 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\AdobeCollabSync.POL 7168 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Annots.POL 506368 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\BRdlang32.POL 55296 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Checkers.POL 124928 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\DigSig.POL 130048 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\DVA.POL 18432 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\eBook.POL 7168 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\EScript.POL 40960 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\IA32.POL 3584 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\makeaccessible.POL 74752 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Multimedia.POL 79360 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\pddom.POL 10752 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\PPKLite.POL 521728 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\RdLang32.POL 1379840 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\ReadOutLoud.POL 11264 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\reflow.POL 4608 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\SaveAsRTF.POL 18432 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Search.POL 24064 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\SendMail.POL 15872 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\DEXShare.asfx 32684 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx 614 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Spelling.POL 10240 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\updater.POL 11776 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\WebLink.POL 29184 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\logsession.dll 368096 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\LogTransport2.exe 315872 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFPrevHndlr.dll 88992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFSigQFormalRep.pdf 468206 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pe.dll 1629576 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Accessibility.api 519267 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\adobepdf.xdc 45935 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\AdobePDF417.pmp 109056 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\DataMatrix.pmp 521216 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm\PMP\QRCode.pmp 78848 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroForm.api 12394595 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\AcroSign.prc 8574 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf 57218 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf 40726 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf 108763 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Dynamic.pdf 36986 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Faces.pdf 33013 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Pointers.pdf 46897 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\SignHere.pdf 327673 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Standard.pdf 115957 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\StandardBusiness.pdf 67699 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\Words.pdf 112498 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annots.api 6103651 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Checkers.api 861283 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\DigSig.api 1461347 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\DVA.api 150115 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\eBook.api 51299 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\EScript.api 1753699 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\IA32.api 99427 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\MakeAccessible.api 2312803 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\Flash.mpp 120832 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\MCIMPP.mpp 93696 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\QuickTime.mpp 278528 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\WindowsMedia.mpp 218112 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\Flash.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\Mcimpp.POL 8192 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\QuickTime.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP_POL\WindowsMedia.POL 2560 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia.api 1526883 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\PDDom.api 429667 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\PPKLite.api 7632483 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\ReadOutLoud.api 112227 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\reflow.api 347747 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\SaveAsRTF.api 406627 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Search.api 430691 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\SendMail.api 157795 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Spelling.api 278115 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Updater.api 169571 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\weblink.api 305251 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\2d.x3d 552840 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\3difr.x3d 269712 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\drvDX9.x3d 814992 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\drvSOFT.x3d 218000 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prc 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prc\MyriadCAD.otf 78276 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\prcr.x3d 3150224 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins3d\tesselate.x3d 22424 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pmd.cer 420 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe 35736 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\rt3d.dll 2215312 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\RTC.der 1098 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ScCore.dll 589712 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\DEXShare.spi 1119017 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg 584045 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\SPPlugins 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\SPPlugins\ADMPlugin.apl 1396736 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll 249232 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_received.gif 615 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_sent.gif 909 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\add_reviewer.gif 1338 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\bl.gif 83 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\br.gif 82 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\create_form.gif 1194 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\distribute_form.gif 821 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\email_all.gif 1443 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\email_initiator.gif 1360 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\ended_review_or_form.gif 807 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\end_review.gif 900 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_distributed.gif 613 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\forms_super.gif 552 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\form_responses.gif 969 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\info.gif 578 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\main.css 11930 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\open_original_form.gif 806 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\pdf.gif 480 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviewers.gif 1452 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_joined.gif 914 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\reviews_super.gif 814 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_browser.gif 1151 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_email.gif 1405 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_same_reviewers.gif 962 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\review_shared.gif 1365 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\rss.gif 222 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_issue.gif 576 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_lg.gif 1255 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\server_ok.gif 225 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\stop_collection_data.gif 915 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\submission_history.gif 906 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\tl.gif 85 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\tr.gif 85 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\trash.gif 1161 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOffNotificationInAcrobat.gif 824 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOffNotificationInTray.gif 995 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOnNotificationInAcrobat.gif 831 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\turnOnNotificationInTray.gif 1002 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Tracker\warning.gif 369 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ViewerPS.dll 17304 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\Reader\wow_helper.exe 73624 bytes executable File C:\Program Files (x86)\Adobe\Reader 10.0\ReadMe.htm 16758 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\ReadMePOL.htm 17476 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap\Identity-H 8228 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\CMap\Identity-V 2761 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\ENUtxt.pdf 7582 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\AdobePiStd.otf 89660 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-Bold.otf 37524 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-BoldOblique.otf 38984 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd-Oblique.otf 39332 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\CourierStd.otf 37860 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-Bold.otf 217028 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-BoldIt.otf 257148 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-It.otf 258056 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MinionPro-Regular.otf 217280 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-Bold.otf 98056 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-BoldIt.otf 101744 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-It.otf 100396 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\MyriadPro-Regular.otf 96560 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\SY______.PFM 672 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\zx______.pfm 683 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\PFM\zy______.pfm 684 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\SY______.PFB 34705 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\ZX______.PFB 75573 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Font\ZY______.PFB 96418 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2\DisplayLanguageNames.pl.txt 28246 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\LanguageNames2\DisplayLanguageNames.pl_PL.txt 28246 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol.fca 972 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol.hyp 118784 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol103.hsp 720111 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\pol32.clx 32766 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\SaslPrep 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\SaslPrep\SaslPrepProfile_norm_bidi.spp 13724 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU\icudt26l.dat 214512 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe\symbol.txt 10381 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Adobe\zdingbat.txt 11932 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CENTEURO.TXT 12948 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CORPCHAR.TXT 18952 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CROATIAN.TXT 13552 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\CYRILLIC.TXT 13432 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\GREEK.TXT 13355 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ICELAND.TXT 14204 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMAN.TXT 14423 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\ROMANIAN.TXT 14792 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\SYMBOL.TXT 15731 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\TURKISH.TXT 12825 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\Mac\UKRAINE.TXT 4634 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1250.TXT 9828 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1251.TXT 9503 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1252.TXT 9653 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1253.TXT 9236 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1254.TXT 9644 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1257.TXT 9516 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\Mappings\win\CP1258.TXT 9506 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Setup Files 0 bytes File C:\Program Files (x86)\Adobe\Reader 10.0\Setup Files\{AC76BA86-7AD7-1045-7B44-AA1000000001} 0 bytes File C:\Program Files (x86)\Amazon\ABB\AmazonChrome-lenovo-abb.crx 93373 bytes File C:\Program Files (x86)\Amazon Browser Bar 0 bytes File C:\Program Files (x86)\Amazon Browser Bar\AlxSSBPS.dll 49968 bytes executable File C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll 1531184 bytes executable File C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.Uninstall.exe 86488 bytes executable File C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBarSSB.3.0.dll 462128 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll 64928 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll 63912 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.POL (size mismatch) 312320/305152 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll 394136 bytes File C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL 300544 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AcrobatUpdater.exe 319400 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeExtractFiles.dll 70584 bytes executable File C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\ReaderUpdater.exe 319400 bytes executable File C:\Program Files (x86)\Common Files\Adobe\Help\en_us 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X\using 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\en_us\reader\X\using\helpmap.txt 721 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X\using 0 bytes File C:\Program Files (x86)\Common Files\Adobe\Help\pl_pl\reader\X\using\helpmap.txt 548 bytes File C:\Program Files (x86)\Common Files\Adobe\HelpCfg\en_US\Reader_10.0.helpcfg 344 bytes File C:\Program Files (x86)\Common Files\Adobe\HelpCfg\pl_PL\Reader_10.0.helpcfg 349 bytes File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe (size mismatch) 129408/389808 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll (size mismatch) 13413248/19860144 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe (size mismatch) 102272/362672 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\AdobeCP.dll 5497216 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\adobecp.vch 639919 bytes File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\AdobeCP15.dll (size mismatch) 3507584/3507512 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\airappinstaller.exe (size mismatch) 53632/310960 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll (size mismatch) 8797056/19427504 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\template.exe (size mismatch) 59392/62464 bytes executable File C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\WebKit.dll (size mismatch) 4771200/4887216 bytes executable File C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe (size mismatch) 610436/614532 bytes executable File C:\Program Files (x86)\Common Files\Intel\Media SDK 0 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1 0 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0 0 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\c.cpa 928775 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\cpa.vp 993 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\dev.vp 44137 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\he_32.vp 10301 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\h_32.vp 9461 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\libmfxhw32-s1.dll 12577720 bytes executable File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_h264vd_32.dll 237568 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_h264ve_32.dll 258048 bytes executable File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_mp2vd_32.dll 237056 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_vc1vd_32.dll 237568 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\mfx_mft_vpp_32.dll 246784 bytes executable File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\m_32.vp 9464 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\v1_32.vp 9436 bytes File C:\Program Files (x86)\Common Files\Intel\Media SDK\s1\2.0\vp_32.vp 9862 bytes File C:\Program Files (x86)\Common Files\microsoft shared\VC\msdia80.dll (size mismatch) 625152/641536 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avcodec-52.dll 1846344 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avformat-52.dll 203848 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\avutil-50.dll 104520 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome.dll 25917496 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_frame_helper.dll 55864 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_frame_helper.exe 89144 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\chrome_launcher.exe 92216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\d3dcompiler_43.dll 2106216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\d3dx9_43.dll 1998168 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Extensions 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Extensions\external_extensions.json 99 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\flashplayercplapp.cpl 404640 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\gcswf32.dll 6333088 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\icudt.dll 9075768 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer\chrome.7z 83850019 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Installer\setup.exe 1271352 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\libegl.dll 106552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\libglesv2.dll 496184 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales 0 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hi.dll 371256 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\am.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ar.dll 308792 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\bg.dll 366136 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\bn.dll 366648 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ca.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\cs.dll 321080 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\da.dll 311352 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\de.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\el.dll 394808 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\en-GB.dll 294968 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\en-US.dll 294456 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\es-419.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\es.dll 338488 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\et.dll 298552 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fa.dll 324152 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fi.dll 309304 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fil.dll 341560 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\fr.dll 343096 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\gu.dll 356920 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\he.dll 279608 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hr.dll 312376 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\hu.dll 331320 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\id.dll 310328 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\it.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ja.dll 242744 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\kn.dll 384568 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ko.dll 228920 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\lt.dll 318520 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\lv.dll 316472 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ml.dll 447544 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\mr.dll 360504 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\nb.dll 309304 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\nl.dll 327224 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pl.dll 332856 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pt-BR.dll 322616 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\pt-PT.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ro.dll 334904 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ru.dll 358456 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sk.dll 331832 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sl.dll 308280 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sr.dll 345144 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sv.dll 307256 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\sw.dll 282168 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\ta.dll 411704 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\te.dll 376376 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\th.dll 355384 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\tr.dll 318008 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\uk.dll 348216 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\vi.dll 322104 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\zh-CN.dll 194104 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\Locales\zh-TW.dll 193080 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\nacl64.dll 2452536 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\nacl64.exe 1476664 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\npchrome_frame.dll 6212152 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\pdf.dll 3649592 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\plugin.vch 498627 bytes File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\ppgooglenaclpluginchrome.dll 329272 bytes executable File C:\Program Files (x86)\Google\Chrome\Application\12.0.742.112\resources.pak 2439126 bytes File C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (size mismatch) 1012792/941720 bytes executable File C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (size mismatch) 182768/194032 bytes executable <-- ROOTKIT !!! File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_zh-CN_64_AFEA62AEFC56F445.dll 707248 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_bg_4074563322A92B86.dll 554672 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ca_48758D4284E1CF09.dll 541872 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_cs_0F04F96F707F23F4.dll 540848 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_da_97D33C0C858471F9.dll 531120 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_de_8251A7D27AF3323C.dll 525488 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_el_F41C324996B886C6.dll 589488 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en-GB_A7584E1CF049BD7B.dll 523952 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll 2013360 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_es_2BE8A68F55B395DD.dll 542384 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fil_0071BC6018071578.dll 547504 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fi_78E90CBF86D1F6EA.dll 535728 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_fr_9DEC13D2629B5A08.dll 550064 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hi_67E1FE88C4333F7B.dll 592560 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hr_988409DD50190882.dll 532144 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_hu_18A7006EF2B488CA.dll 544944 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_id_98364288BBB09CC5.dll 531632 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_is_60A4F5F49ACB6000.dll 537776 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_it_A82B711CFC49E9DD.dll 538288 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ja_823F21A18D628A46.dll 549040 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleCld_26623DE26D4DBD2D.dll 1206960 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleQuickSearchBoxSetup_F8DB49E787CC0771.exe 2938352 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar.7.1.1821.1806.manifest.xml 16985 bytes File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_D1B8F90352BD52A9.dll 3082416 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_64_136C3706C4509D97.dll 4663472 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_ja_32_D7397CC65FA11CF0.dll 317616 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_ja_64_21276A3BC060C732.dll 416944 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_ext_zh-CN_32_A5B37DD91AFCF7CD.dll 555184 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_et_E78F15F19B24A4D5.dll 530608 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ko_D905A071ABFF1B7B.dll 515760 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sl_52DDAFE99637F72B.dll 535216 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_lt_C404E000E80AB3DF.dll 540336 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_lv_EA1628B75E1094DC.dll 537264 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_nl_3AAC294F9909F6B2.dll 536240 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_no_BB2DD1B0E5F85CDE.dll 532144 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pl_BFB5E9018AAD2B4D.dll 543408 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pt-BR_14B054AF84DB147F.dll 543408 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_pt-PT_94ACE028001DE37F.dll 547504 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ro_806BC80260FF2B38.dll 549040 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_ru_67B78656D7BF50B9.dll 580272 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sk_8E484E435DB524A5.dll 546992 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sr_90B923AEEB433763.dll 560816 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_sv_C2D96AA6195FD1BC.dll 533680 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_th_7735E13BE92FAF8E.dll 587952 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_tr_C1231F6B5AF97FA1.dll 536752 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_uk_0F7FD6DA968F6862.dll 569520 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_vi_37252089E2D4FAD9.dll 551600 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_zh-CN_10E08B6D7CB47AFE.dll 924848 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_zh-TW_1965F9F500EFCFCD.dll 491696 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_EAA6E347FFC35CC8.exe 1053872 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_8AD791F283771CB0.exe 307376 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_851D90A00F31A295.exe 399024 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_32_79A4E6A8AACC0F12.dll 305328 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbar_64_9F1D475DC3704B46.dll 410288 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_5898FABCFA121C11.exe 182768 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_90698EA083D01143.exe 568472 bytes File C:\Program Files (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_86D23231A3A85F4A.exe 1706552 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (size mismatch) 307376/308336 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe (size mismatch) 399024/399472 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (size mismatch) 305328/193136 bytes executable File C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (size mismatch) 410288/255088 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642 0 bytes File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\gth.dll 49208 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\gtn.dll 150072 bytes executable File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\Readme.url 133 bytes File C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll 1007160 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57 0 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_am.dll 22680 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ar.dll 24728 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_bg.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_bn.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ca.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_cs.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_da.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_de.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_el.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_en-GB.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_en.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_es-419.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_es.dll 28824 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_et.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fa.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fi.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fr.dll 28312 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_gu.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hi.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hr.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_hu.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_id.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_is.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_it.dll 28312 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_iw.dll 24216 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ja.dll 22680 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_kn.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ko.dll 22168 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_lt.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_lv.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ml.dll 29336 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_mr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleCrashHandler.exe 140952 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdate.exe 136176 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateBroker.exe 59032 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateHelper.msi 25088 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\GoogleUpdateOnDemand.exe 59032 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_nl.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_no.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pl.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pt-BR.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_pt-PT.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ro.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ru.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sk.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sl.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sv.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_sw.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ta.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_te.dll 27288 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_th.dll 25752 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_tr.dll 26776 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_uk.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ur.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_vi.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_zh-CN.dll 20120 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_zh-TW.dll 20120 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll 235672 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\psmachine.dll 138904 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\psuser.dll 138904 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdate.dll 798872 bytes File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_fil.dll 27800 bytes executable File C:\Program Files (x86)\Google\Update\1.3.21.57\goopdateres_ms.dll 26264 bytes executable File C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\12.0.742.112 0 bytes File C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\12.0.742.112\chrome_installer.exe 22267448 bytes executable File C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (size mismatch) 136176/144200 bytes executable <-- ROOTKIT !!! File C:\Program Files (x86)\Google\Update\Offline 0 bytes File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\ar-SA\setup.exe.mui (size mismatch) 27136/35840 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\cs-CZ\setup.exe.mui (size mismatch) 30208/38912 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\da-DK\setup.exe.mui (size mismatch) 30720/39424 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\de-DE\setup.exe.mui (size mismatch) 32768/41472 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\el-GR\setup.exe.mui (size mismatch) 34304/43520 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\en-US\setup.exe.mui (size mismatch) 18944/27648 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\es-ES\setup.exe.mui (size mismatch) 32768/41984 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\fi-FI\setup.exe.mui (size mismatch) 29696/38912 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\fr-FR\setup.exe.mui (size mismatch) 34304/43008 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\he-IL\setup.exe.mui (size mismatch) 25600/34816 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\hr-HR\setup.exe.mui (size mismatch) 31744/40960 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\hu-HU\setup.exe.mui (size mismatch) 31744/40448 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\it-IT\setup.exe.mui (size mismatch) 32256/41472 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\ja-JP\setup.exe.mui (size mismatch) 22016/30720 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\ko-KR\setup.exe.mui (size mismatch) 20992/30208 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\nb-NO\setup.exe.mui (size mismatch) 30208/39424 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\nl-NL\setup.exe.mui (size mismatch) 33280/42496 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\pl-PL\setup.exe.mui (size mismatch) 31744/40448 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\pt-BR\setup.exe.mui (size mismatch) 31232/40448 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\pt-PT\setup.exe.mui (size mismatch) 32256/41472 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\ro-RO\setup.exe.mui (size mismatch) 32256/41472 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\ru-RU\setup.exe.mui (size mismatch) 29696/38912 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\Setup.exe (size mismatch) 1059608/1100720 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\sk-SK\setup.exe.mui (size mismatch) 31232/39936 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\sl-SI\setup.exe.mui (size mismatch) 30720/39424 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\sv-SE\setup.exe.mui (size mismatch) 29696/38400 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\th-TH\setup.exe.mui (size mismatch) 29184/37888 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\tr-TR\setup.exe.mui (size mismatch) 31232/39936 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\x64\Drv64.exe (size mismatch) 184600/197040 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\zh-CN\setup.exe.mui (size mismatch) 17920/27136 bytes executable File C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\uninstall\zh-TW\setup.exe.mui (size mismatch) 18432/27136 bytes executable File C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe (size mismatch) 13112/16336 bytes executable File C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll (size mismatch) 12088/13264 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1025\OOBEIntl.dll (size mismatch) 20848/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1026\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1028\OOBEIntl.dll (size mismatch) 19312/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1029\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1030\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1031\OOBEIntl.dll (size mismatch) 21872/21096 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1032\OOBEIntl.dll (size mismatch) 22384/21096 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1033\OOBEIntl.dll (size mismatch) 19824/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1035\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1036\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1037\OOBEIntl.dll (size mismatch) 20848/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1038\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1040\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1041\OOBEIntl.dll (size mismatch) 20336/19560 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1042\OOBEIntl.dll (size mismatch) 19824/19560 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1043\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1044\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1045\OOBEIntl.dll (size mismatch) 22384/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1046\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1048\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1049\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1050\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1051\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1053\OOBEIntl.dll (size mismatch) 21360/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1054\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1055\OOBEIntl.dll (size mismatch) 21360/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1058\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1060\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1061\OOBEIntl.dll (size mismatch) 21360/20072 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1062\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1063\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1081\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\1087\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2052\OOBEIntl.dll (size mismatch) 19312/19048 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2070\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\2074\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\3082\OOBEIntl.dll (size mismatch) 21872/20584 bytes executable File C:\Program Files (x86)\Microsoft Office\Options14\OOBESTUB.EXE (size mismatch) 81792/82560 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lv\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\agcore.dll 5921792 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\agcp.exe 15688 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ar\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\bg\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ca\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\coreclr.dll 3516928 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\coregen.exe 73552 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\cs\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\da\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\de\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\el\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\es\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\et\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\eu\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fi\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\fr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\he\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\hu\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\id\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\it\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ja\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ko\system.resources.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\lt\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Microsoft.VisualBasic.dll 253952 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ms\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorlib.dll 1589248 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorlib.ni.dll 6186496 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\nl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\no\system.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll 1013248 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll 760832 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\pt-BR\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ro\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\ru\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Silverlight.Configuration.exe 348528 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\Silverlight.ConfigurationUI.dll 747520 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sk\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\mscorrc.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sl\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\SLMSPRBootstrap.dll 426336 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\slr.dll.managed_manifest 5587 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Cyrl-CS\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sr-Latn-CS\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\sv\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Core.dll 536576 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Core.ni.dll 2364928 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\system.dll 233472 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Net.dll 225280 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Net.ni.dll 650240 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ni.dll 664576 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.dll 413696 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Runtime.Serialization.ni.dll 1186304 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.dll 520192 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.ni.dll 1598464 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.Web.dll 73728 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.ServiceModel.Web.ni.dll 137728 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.Browser.dll 143360 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.Browser.ni.dll 373760 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.dll 1462272 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Windows.ni.dll 4453888 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Xml.dll 319488 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\System.Xml.ni.dll 843776 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\th\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\tr\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\mscorlib.resources.dll 5120 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\uk\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\mscorrc.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\vi\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\mscorrc.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hans\system.resources.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant 0 bytes File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\Microsoft.VisualBasic.resources.dll 4096 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\mscorlib.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\mscorrc.dll 3584 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\zh-Hant\system.resources.dll 4608 bytes executable File C:\Program Files (x86)\Microsoft Silverlight\xapauthenticodesip.dll (size mismatch) 19808/61608 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\detoured.dll (size mismatch) 4096/20536 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\Nvd3d9wrap.dll (size mismatch) 236352/154952 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\coprocmanager\nvdxgiwrap.dll (size mismatch) 182080/105328 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe 1022784 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 2458944 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\WLMerger.exe 190272 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\cudart32_41_4.dll 428392 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\cudart64_41_0.dll 593256 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXDevice64.dll (size mismatch) 74088/675064 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll (size mismatch) 71528/57592 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll (size mismatch) 74600/65784 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll (size mismatch) 83816/73976 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader64.dll (size mismatch) 89448/90872 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.1\PhysXCooking.dll (size mismatch) 391016/362744 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.1\PhysXCore.dll (size mismatch) 3942248/5154552 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\C22346819C37\PhysXCore.dll (size mismatch) 4049768/9884408 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\DO_NOT_MANUALLY_DELETE_ANY_SUBFOLDERS.txt 1 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.1 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.1\NxCooking.dll 230688 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.1\PhysXCore.dll 1303840 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.2 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.2\NxCooking.dll 316704 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.2\PhysXCore.dll 1377568 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.3 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.3\NxCooking.dll 316704 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.3.3\PhysXCore.dll 1377568 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.0 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.0\NxCooking.dll 341280 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.0\PhysXCore.dll 1869088 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.1 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.1\NxCooking.dll 341280 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.1\PhysXCore.dll 1869088 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.4 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.4\NxCooking.dll 341280 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.4.4\PhysXCore.dll 1877280 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.0 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.0\PhysXCooking.dll 333088 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.0\PhysXCore.dll 2295072 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.1 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.1\PhysXCooking.dll 337184 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.1\PhysXCore.dll 2311456 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.3 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.3\PhysXCooking.dll 337184 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.3\PhysXCore.dll 2311456 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.4 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.4\PhysXCooking.dll 337184 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.5.4\PhysXCore.dll 2340128 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.0 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.0\PhysXCooking.dll 333088 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.0\PhysXCore.dll 2393376 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.1 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.1\PhysXCooking.dll 333088 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.1\PhysXCore.dll 2397472 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.2 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.2\PhysXCooking.dll 337184 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.2\PhysXCore.dll 2475296 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.3 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.3\PhysXCooking.dll 337184 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.3\PhysXCore.dll 2503968 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.4 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.4\PhysXCooking.dll 410912 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.6.4\PhysXCore.dll 2946336 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.0 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.0\PhysXCooking.dll 386336 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.0\PhysXCore.dll 2659616 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.2 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.2\PhysXCooking.dll 385792 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.2\PhysXCore.dll 2724608 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.3\PhysXCooking.dll (size mismatch) 391016/362744 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.3\PhysXCore.dll (size mismatch) 4093800/5311736 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.4\PhysXCooking.dll (size mismatch) 391016/362744 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.4\PhysXCore.dll (size mismatch) 4052840/5264120 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.5\PhysXCooking.dll (size mismatch) 391016/362744 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.6\PhysXCooking.dll (size mismatch) 399208/374008 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.7.6\PhysXCore.dll (size mismatch) 4114280/5331192 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.0\PhysXCooking.dll (size mismatch) 391016/362232 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.0\PhysXCore.dll (size mismatch) 4302696/5520120 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.1\PhysXCooking.dll (size mismatch) 391016/363256 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.1\PhysXCore.dll (size mismatch) 4519784/5823736 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.3\PhysXCooking.dll (size mismatch) 362344/339192 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.3\PhysXCooking64.dll (size mismatch) 458600/412408 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.3\PhysXCore.dll (size mismatch) 3438440/4785400 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\PhysX\Engine\v2.8.3\PhysXCore64.dll (size mismatch) 4955496/5952248 bytes executable File C:\Program Files (x86)\NVIDIA Corporation\Update Common 0 bytes File C:\Program Files (x86)\NVIDIA Corporation\Update Common\EasyDaemonAPIU.dll 639296 bytes executable File C:\ProgramData\Adobe\Acrobat 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security 0 bytes File C:\ProgramData\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata 479 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001} 0 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\ABCPY.INI 1729 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\AcroRead.msi 2328576 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\Data1.cab 124461271 bytes File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\setup.exe 1560520 bytes executable File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1045-7B44-AA1000000001}\Setup.ini 292 bytes File C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\404b466b6bfefd5de0c0a19f33336d46_761f9581-5d42-4ed3-9841-0f5bbef59f97 2085 bytes File C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll (size mismatch) 17816/23256 bytes executable File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr 15660 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000A.log 1048576 bytes File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wsb 65536 bytes File C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000002d.db 192648 bytes File C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000002e.db 191120 bytes File C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000030.db 191120 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2441 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk 2284 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Odinstaluj Google Chrome.lnk 2433 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Solution Center 0 bytes File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Solution Center\Lenovo Solution Center.lnk 2024 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0c99841d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0c99841d\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0e68473c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0e68473c\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0f99e204 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0f99e204\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_10231a18 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_10231a18\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_10fec571 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_10fec571\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_11330ff8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_11330ff8\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_11378fd1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_11378fd1\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_128714c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_128714c9\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1351dd85 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1351dd85\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_139a3764 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_139a3764\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_14df3821 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_14df3821\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_08d4d45e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_08d4d45e\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_0b8c499d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_0b8c499d\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_0d4b1747 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82ac49ed4184ee95e9a746829e8f5db5ff7088_0d4b1747\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82e3e82072a45ae722b62c92e038e63a2d9649ce_0f8c1239 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_82e3e82072a45ae722b62c92e038e63a2d9649ce_0f8c1239\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_05f031ba 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_05f031ba\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0875cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0875cd0e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_09064c5a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_09064c5a\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0a4aa488 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0a4aa488\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0cfec7a1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0cfec7a1\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_72a5dd8f678f4fba78219b4e2695b0f132632b4_05a375fa 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_72a5dd8f678f4fba78219b4e2695b0f132632b4_05a375fa\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_72a5dd8f678f4fba78219b4e2695b0f132632b4_0ec3cf32 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_72a5dd8f678f4fba78219b4e2695b0f132632b4_0ec3cf32\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7634823dfb51fd1e88513fc31ba96c4ffaee590_0a150c4f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7634823dfb51fd1e88513fc31ba96c4ffaee590_0a150c4f\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_0c3ed98c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_0c3ed98c\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7ac1d19b3ba62a9f28e05c59b6c7677774b532b0_0ecbadeb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7ac1d19b3ba62a9f28e05c59b6c7677774b532b0_0ecbadeb\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7bc01ca62044d5bb70505c52d5128ec6221f7c_06be0c50 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7bc01ca62044d5bb70505c52d5128ec6221f7c_06be0c50\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7f1fcd428766da3a7de8ac658cae1f7922363a3_0d462de2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7f1fcd428766da3a7de8ac658cae1f7922363a3_0d462de2\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7fbd1b13fa5e72ffe4ae885ee613929847bda03d_0570958b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7fbd1b13fa5e72ffe4ae885ee613929847bda03d_0570958b\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0abe846b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0abe846b\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0afb367a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0afb367a\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b336631 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b336631\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b363330 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b363330\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b6bbc2d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0b6bbc2d\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0bdac9c4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0bdac9c4\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0eb32de2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0eb32de2\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0ebb39e4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0ebb39e4\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_15181c79 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_15181c79\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_1604b07a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_1604b07a\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_16445b1b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_16445b1b\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17324888 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17324888\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17aa7dd9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17aa7dd9\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17c40010 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17c40010\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17f9841d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_17f9841d\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_1915e049 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_1915e049\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_074efe5b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_074efe5b\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_093f3987 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_093f3987\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0ae992be 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0ae992be\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b1c4eda 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b1c4eda\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b204568 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b204568\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b204816 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b204816\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b24537c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b24537c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b64335e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b64335e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b70558e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b70558e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b74869c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b74869c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b7c3e95 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b7c3e95\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0af015b1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0af015b1\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0b1b46a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0b1b46a0\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0ddeef1e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0ddeef1e\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0e3b2db4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0e3b2db4\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_09d5930c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_09d5930c\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_16df0a34 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_16df0a34\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_17969290 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_49987c602ff05afc90aa8f8473f959e389b6ace6_17969290\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4b9c5c28372b76f562821ab0f046f4dafad9ec_0772eadb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4b9c5c28372b76f562821ab0f046f4dafad9ec_0772eadb\Report.wer 2506 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_515aceb3ba2eebfc26b5a6a6bf29581f3c286e_1228d960 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_515aceb3ba2eebfc26b5a6a6bf29581f3c286e_1228d960\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_51888f881b8f858fc49e29a111d9d21dd6abc5d_08507a3e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_51888f881b8f858fc49e29a111d9d21dd6abc5d_08507a3e\Report.wer 2506 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_0b7ef640 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_0b7ef640\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_533111acc1c372b41e7d5ab2b2d8e1de466d978_08f72e50 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_533111acc1c372b41e7d5ab2b2d8e1de466d978_08f72e50\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_57721537cb5999723b6967c42d9030a676e77d34_0b927629 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_57721537cb5999723b6967c42d9030a676e77d34_0b927629\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_595cc282c63c35362731494929e43498d4115_07df91f2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_595cc282c63c35362731494929e43498d4115_07df91f2\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_595cc282c63c35362731494929e43498d4115_0e0d50cf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_595cc282c63c35362731494929e43498d4115_0e0d50cf\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6013b333ee54aa869d8f8645264ab9aad27df18a_093bf19f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6013b333ee54aa869d8f8645264ab9aad27df18a_093bf19f\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_62763d6f398e366f5e245ccd7878b0bfa7a040d5_09b1c0ef 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_62763d6f398e366f5e245ccd7878b0bfa7a040d5_09b1c0ef\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0bb9f7d5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0bb9f7d5\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0bf8c64a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0bf8c64a\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0c4e25a8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0c4e25a8\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0cbea1f9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0cbea1f9\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_981221c826cd9674d74e7ed77a4e4dd5107686e9_0a8ad45f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_981221c826cd9674d74e7ed77a4e4dd5107686e9_0a8ad45f\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_991899e661913c521aa53523aa9962a0c9b2558_0599c0de 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_991899e661913c521aa53523aa9962a0c9b2558_0599c0de\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9c4b21aa3eef435576873eaa1f9c76441db438_057d1131 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9c4b21aa3eef435576873eaa1f9c76441db438_057d1131\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9c9e3fc417bb1174531638617cd2216203976c_0bbed411 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9c9e3fc417bb1174531638617cd2216203976c_0bbed411\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9e765d914ef61f10ff60f9af4b2a6dad7293af13_0f088def 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9e765d914ef61f10ff60f9af4b2a6dad7293af13_0f088def\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9ee24f235d85e75241e8fd6c78c4b11de491a7ef_0b81dc69 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9ee24f235d85e75241e8fd6c78c4b11de491a7ef_0b81dc69\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9ee5bafb9a33f9292982db470b051aab3743a1e_0dd28610 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9ee5bafb9a33f9292982db470b051aab3743a1e_0dd28610\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9f4fceee6f483b48b3391cac933dba732ecfe236_0d0625d7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_9f4fceee6f483b48b3391cac933dba732ecfe236_0d0625d7\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09ab1370 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09ab1370\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09b6a533 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09b6a533\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09c24cd7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09c24cd7\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09cff391 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09cff391\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09d7f4c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09d7f4c9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e080b3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e080b3\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e2c447 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e2c447\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e3730d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09e3730d\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09ea141c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09ea141c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f3e53f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f3e53f\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f3fc0a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f3fc0a\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f625b8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09f625b8\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fa4d35 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fa4d35\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fb0d68 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fb0d68\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fbe83c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fbe83c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fe846b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09fe846b\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0a4346 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0a4346\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0e204c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0e204c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b25360d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b25360d\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b461728 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b461728\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b5f8f05 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b5f8f05\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0be37a0f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0be37a0f\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0c8c6b11 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0c8c6b11\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0f1f39f3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0f1f39f3\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0f6b5dd8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0f6b5dd8\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3614f64a6a7e5cac07f1a06daac5620b1bb33_0ce07f5c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3614f64a6a7e5cac07f1a06daac5620b1bb33_0ce07f5c\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_04cc404a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_04cc404a\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0a7e3dab 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0a7e3dab\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0b5d640f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0b5d640f\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0c49cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37be4351c24611c1d77be25a99794a2b704c0_0c49cd0e\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37eae1641986c793f6f122d419ed11c3fca76e1_05e47f7b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_37eae1641986c793f6f122d419ed11c3fca76e1_05e47f7b\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_08b02480 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_08b02480\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_08e5f7d5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_08e5f7d5\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_09f13255 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_09f13255\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a493052 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a493052\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a560453 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a560453\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a6124ce 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0a6124ce\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b05f7d5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b05f7d5\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b560ede 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b560ede\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b731b6c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0b731b6c\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11bb7966 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11bb7966\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11ef0a44 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11ef0a44\Report.wer 3096 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_17596a5d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_17596a5d\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a2ebecb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a2ebecb\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a34c050 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a34c050\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1bf533bd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1bf533bd\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_00ae8841 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_00ae8841\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_026410c2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_026410c2\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0368d1bf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0368d1bf\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_03f94172 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_03f94172\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_07050212 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_07050212\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0877c467 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0877c467\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_089b88fd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_089b88fd\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_08b39693 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_08b39693\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0934eeb1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0934eeb1\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_09b71b6c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_09b71b6c\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0a5b363c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0a5b363c\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0a860453 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0a860453\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0aa71d8e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0aa71d8e\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_042b192a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_042b192a\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_04b655dc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_04b655dc\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0592d2e7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0592d2e7\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_063b62d7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_063b62d7\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_072672af 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_072672af\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_077415b1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_077415b1\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0800e494 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0800e494\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_08e9abe7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_08e9abe7\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0a038084 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0a038084\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0e0e3fce 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0e0e3fce\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b0e6a85 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b0e6a85\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0c513cd1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0c513cd1\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_07421978 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_07421978\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0ae23fec 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0ae23fec\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_0a7455dc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_0a7455dc\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_081f4681 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_081f4681\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0cd22589 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_0cd22589\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7fbd1b13fa5e72ffe4ae885ee613929847bda03d_0d273027 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_7fbd1b13fa5e72ffe4ae885ee613929847bda03d_0d273027\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_063e4346 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_063e4346\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_077015b1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_077015b1\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_07ce145a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_07ce145a\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_07eb7f7b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_07eb7f7b\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0914202c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0914202c\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09243217 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09243217\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09b2558e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09b2558e\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09e23294 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_09e23294\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a24fce4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a24fce4\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a4b7ff8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a4b7ff8\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_1999de5e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_1999de5e\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_1aa25067 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_1aa25067\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070020_133293676e2bfb2e1339b90e10877e3ee210f6_19cac247 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070020_133293676e2bfb2e1339b90e10877e3ee210f6_19cac247\Report.wer 2316 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070020_40a096bcf06bc3714ab4a4bee481d954856470_1493e5e1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070020_40a096bcf06bc3714ab4a4bee481d954856470_1493e5e1\Report.wer 2366 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_b51e741227d863db86a717d3016470273a478f_17c29f79 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_b51e741227d863db86a717d3016470273a478f_17c29f79\Report.wer 2366 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_dcf186151bd943b0c0d444981ecf4487aa9c772_13cf2931 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_dcf186151bd943b0c0d444981ecf4487aa9c772_13cf2931\Report.wer 2292 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_e0afddd1b0f93f5f6dc8a61d6c3f5f7b31282679_1039bebc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x800705b4_e0afddd1b0f93f5f6dc8a61d6c3f5f7b31282679_1039bebc\Report.wer 2296 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0a4ac523 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0a4ac523\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a0f2b63 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a0f2b63\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0b8aa2b4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0b8aa2b4\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a0acc8745169144294c7dd6b81e53a718171_1416345b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a0acc8745169144294c7dd6b81e53a718171_1416345b\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b4976c5b1e333160c87393f13987661de9f6a89a_0bb727f9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b4976c5b1e333160c87393f13987661de9f6a89a_0bb727f9\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0b0d783b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0b0d783b\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_1a7d07bb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_1a7d07bb\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d49a7c90aed2c2ec3e0352ddb29f96b08120b1_0db0e63c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d49a7c90aed2c2ec3e0352ddb29f96b08120b1_0db0e63c\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_080bc457 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_080bc457\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_083845e5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_083845e5\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09213246 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09213246\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_092d8767 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_092d8767\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0935f5a4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0935f5a4\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09527e24 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09527e24\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_095a0453 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_095a0453\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_095d3052 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_095d3052\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_096124ce 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_096124ce\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_096390c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_096390c9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09662d27 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_09662d27\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0995ff35 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0995ff35\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_099a91f2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_099a91f2\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a13fc77 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a13fc77\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a1c31f8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a1c31f8\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a221795 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a221795\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a3672bf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a3672bf\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a395070 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a395070\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a464578 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a464578\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a476631 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a476631\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a4eb5f5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a4eb5f5\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a523d8c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a523d8c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a5bbc2d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a5bbc2d\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a5c1e58 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a5c1e58\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a624c5a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a624c5a\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a6865a5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a6865a5\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a6f69c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a6f69c9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a73a6c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a73a6c9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_0f4b618f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_0f4b618f\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_0f58e945 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_0f58e945\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0222336e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0222336e\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0acc9b83 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0acc9b83\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aee3c92 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aee3c92\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0af2729f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0af2729f\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0af4a0d0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0af4a0d0\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0afa9ccb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0afa9ccb\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0afe4078 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0afe4078\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b0e73a9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b0e73a9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b1709a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b1709a0\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b2d8036 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b2d8036\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b583014 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b583014\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b675ccf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b675ccf\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b7753ca 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b7753ca\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b837619 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0b837619\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0baabbb0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0baabbb0\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_154e4888 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_154e4888\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1626629d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1626629d\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_163f2991 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_163f2991\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_166024cf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_166024cf\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_168780c3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_168780c3\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_169d50dd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_169d50dd\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_17c7c458 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_17c7c458\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_17fc1c79 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_17fc1c79\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_18fe2734 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_18fe2734\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1a26b75f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1a26b75f\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8b976bc39f4d06833bbf516270ffba7231168a_085e9ab9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8b976bc39f4d06833bbf516270ffba7231168a_085e9ab9\Report.wer 3398 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ba7efcfb1526ddd301a5dfdd86e6da215b01910_0223e38b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ba7efcfb1526ddd301a5dfdd86e6da215b01910_0223e38b\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ba7efcfb1526ddd301a5dfdd86e6da215b01910_0b4fe7a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ba7efcfb1526ddd301a5dfdd86e6da215b01910_0b4fe7a0\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bb911579ae48f98c57ef0df62f91dbcf058d5_072449cc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bb911579ae48f98c57ef0df62f91dbcf058d5_072449cc\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bcdc7e9338979d434360338ab811359a2e1e8e4_0500d0e6 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bcdc7e9338979d434360338ab811359a2e1e8e4_0500d0e6\Report.wer 2506 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bdcde28b356f26b99951ef33dbaad2cfb9c5d5_0ace9a5b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_bdcde28b356f26b99951ef33dbaad2cfb9c5d5_0ace9a5b\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_c1155366c7e4dc926de59ee3f64d40c24c9896_073aa6d9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_c1155366c7e4dc926de59ee3f64d40c24c9896_073aa6d9\Report.wer 2506 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_06e46d72 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_06e46d72\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_13977966 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_13977966\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_14964cc0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_14964cc0\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_18b133bd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_18b133bd\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_0769b664 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_0769b664\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_09431af2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_09431af2\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_0c333821 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_0c333821\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_11a5e204 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_11a5e204\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_11b40232 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_11b40232\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_12f18595 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_12f18595\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_149b0ff8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_149b0ff8\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_14ef7087 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_14ef7087\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_04e30c50 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_04e30c50\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_069fe39b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_069fe39b\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_0a33e7b0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ae1a8ffb1ab2ef253efd03c69260be8b178bd8_0a33e7b0\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6bbf6377afc102bee6143bb651bbb8680944521_06e66547 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6bbf6377afc102bee6143bb651bbb8680944521_06e66547\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0499a776 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0499a776\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_07ee1ea7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_07ee1ea7\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0d0a9e90 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0d0a9e90\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0d11cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6da1a3b0794be412f8fd94929bbc8218232398f1_0d11cd0e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ecc1fa58c5dd7590affe3fe9901a70f3f12b9a_0260cd01 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ecc1fa58c5dd7590affe3fe9901a70f3f12b9a_0260cd01\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ecc1fa58c5dd7590affe3fe9901a70f3f12b9a_053e4fc5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6ecc1fa58c5dd7590affe3fe9901a70f3f12b9a_053e4fc5\Report.wer 2488 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f22bdabe512d4979cac79b33956626758c8e91_0d971f14 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f22bdabe512d4979cac79b33956626758c8e91_0d971f14\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_03e8c64a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_03e8c64a\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05aec16a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05aec16a\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05e4ee73 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05e4ee73\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05faace1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_05faace1\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_06272422 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_06272422\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_064e186f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_6f6c327a674fee369f9b6bba6e96468a07fdf9b_064e186f\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a153052 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a153052\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a2124ce 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a2124ce\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a22a5b0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a22a5b0\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a260453 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a260453\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0ae1a2d3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0ae1a2d3\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0ae9ff35 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0ae9ff35\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0af22d27 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0af22d27\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0b6d5070 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0b6d5070\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a0eae7bdc82d3a9e7db9ec7652ff2710d360ec9_0fa1b25d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a0eae7bdc82d3a9e7db9ec7652ff2710d360ec9_0fa1b25d\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a2d2645cfaad83b8487b67c43a1952fab15ad1f_0afcebb5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a2d2645cfaad83b8487b67c43a1952fab15ad1f_0afcebb5\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_098d8fef 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_098d8fef\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a3726b3ab46844d9fcf1f05b5df5a1c0ae1fb_17b30223 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a3726b3ab46844d9fcf1f05b5df5a1c0ae1fb_17b30223\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_0d2dca7f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_0d2dca7f\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_06c75c52 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_06c75c52\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_09de8cf3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_09de8cf3\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_0c01cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_0c01cd0e\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_0f6343e2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a81d39da1cbcbb61242e6d7ab13758d682772011_0f6343e2\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a8b5adb6f0cbac2d328632c870372c112fe81d_09690167 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a8b5adb6f0cbac2d328632c870372c112fe81d_09690167\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a8b5adb6f0cbac2d328632c870372c112fe81d_0ae16400 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_a8b5adb6f0cbac2d328632c870372c112fe81d_0ae16400\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_09c7e5bc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_09c7e5bc\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_01ab5f7d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_01ab5f7d\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b3db28e14c11c99df12b7033213a89ded97ba76b_08b5cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b3db28e14c11c99df12b7033213a89ded97ba76b_08b5cd0e\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a934f66 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0a934f66\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0f1b6122 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0f1b6122\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0ae02dc3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0ae02dc3\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b985697 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0b985697\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11646d82 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_11646d82\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_070b52ff 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_070b52ff\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_099e1064 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_099e1064\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0e2ac7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a0e2ac7\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a827982 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a827982\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a98536c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a98536c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0acb495e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0acb495e\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0bce2d85 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0bce2d85\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0789b5c8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_0789b5c8\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_150e36f8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_150e36f8\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1b2f6f5e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_1b2f6f5e\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_14f04144 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_14f04144\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0a5f95e8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0a5f95e8\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0514780c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_0514780c\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0d59cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0d59cd0e\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_030f85b2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_030f85b2\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b1a3f7f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_34f11a711f30d43d1e51bf689e9530666ca2_0b1a3f7f\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_04547f10 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3b22753b61f8596ff644756cdd090153bcef8af_04547f10\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0e753d00 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_0e753d00\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3ca4183078cbd3cced81915918abe5752a50723d_05e05041 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_3ca4183078cbd3cced81915918abe5752a50723d_05e05041\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_01a7cf32 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_01a7cf32\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0684b421 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0684b421\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_094a4c5a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_094a4c5a\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a337658 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a337658\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a599270 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a599270\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a97e53f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a97e53f\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a97fbfa 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0a97fbfa\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0aa3e83c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0aa3e83c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ab3fc77 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ab3fc77\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ac7f391 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ac7f391\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0f8992cd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0f8992cd\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0914820b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0914820b\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0b11a17c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0b11a17c\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0b299415 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0b299415\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0ecac419 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0ecac419\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0f092f88 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25cb98b26d4ff895021d764a9c31636ba7d2413_0f092f88\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b52ccf4bfa5c96e6c7f7d822c4e410480724845_0ad15937 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b52ccf4bfa5c96e6c7f7d822c4e410480724845_0ad15937\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_047f9230 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_047f9230\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_05b031c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_05b031c9\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_0a51cd0e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_0a51cd0e\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_0bb0f891 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b7dde883e915be8f6bea4ab5f5888ce78e1326_0bb0f891\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_05fbe35c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_05fbe35c\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_069b5051 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_069b5051\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0981b4dd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0981b4dd\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0a31e13a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_0a31e13a\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0a5c01f4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0a5c01f4\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0ef52fb7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0ef52fb7\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0fd592be 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0fd592be\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8bea26dbd2e617c0e38b294fed4a2691ff10ff_06cc6d65 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8bea26dbd2e617c0e38b294fed4a2691ff10ff_06cc6d65\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8d78a896085dfa01db4a3e92f21eafe17416d2_0cac1769 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8d78a896085dfa01db4a3e92f21eafe17416d2_0cac1769\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_046f1b7b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_046f1b7b\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_04fa16ab 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_04fa16ab\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_083ceeb1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_083ceeb1\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_09c13255 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_09c13255\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a0746a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8e50bc23d49361ebc102b17bb2d414b8366963_0a0746a0\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_086a3ce0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_086a3ce0\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_0c6a82a7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_0c6a82a7\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_0f2edee9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f5b87fbab35bddd2f0fe98db8b48f9c58f3b836_0f2edee9\Report.wer 2494 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0134d162 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0134d162\Report.wer 3400 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0a5c335e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0a5c335e\Report.wer 3400 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0b3ba7c3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0b3ba7c3\Report.wer 3400 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0b6e9cda 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f686a82e30eb7ffbbdad76f025db1df513827c9_0b6e9cda\Report.wer 3400 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a6be53f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a6be53f\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a6bfbfa 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a6bfbfa\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a73e83c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a73e83c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a87fc77 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a87fc77\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a97f391 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0a97f391\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a88558e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a88558e\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8a49cb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8a49cb\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8c2dc3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8c2dc3\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8e0ba3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8e0ba3\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8e5f6d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a8e5f6d\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a90336e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a90336e\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a904816 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a904816\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a92a41b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a92a41b\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a944568 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a944568\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0c9f03b8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0c9f03b8\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0cea3fde 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0cea3fde\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_02560fa9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_02560fa9\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_04eb7d69 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_04eb7d69\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_051ab7c9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_051ab7c9\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0624c64a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_0624c64a\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_06be7280 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_06be7280\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_072c40f5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_447112ee33a7cc55cadc505553692f8b3e7e4f_072c40f5\Report.wer 2480 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0bc864f9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fc878b80a9f12c4bb8d2460c3bcc5f44f1e317_0bc864f9\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fcfc372a156d3683dbee9a546c8f84db28481d5_05a4d6df 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_fcfc372a156d3683dbee9a546c8f84db28481d5_05a4d6df\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_16348ce9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_16348ce9\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_169f59a5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_169f59a5\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_18707944 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_18707944\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_19489dda 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_19489dda\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_1a46d099 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_1a46d099\Report.wer 3100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_022950d0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_022950d0\Report.wer 2182 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_0d0c088b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_0d0c088b\Report.wer 2182 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_0f96b250 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_0f96b250\Report.wer 2182 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_10380d99 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_10380d99\Report.wer 2182 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_15e96192 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_1dd1a9dd19a15dcded3cdd79e8932cde82322c_15e96192\Report.wer 2182 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0ac29290 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0ac29290\Report.wer 3096 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0cbe4cdf 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0cbe4cdf\Report.wer 2202 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0ff9932b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0ff9932b\Report.wer 3096 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b233987 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b233987\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b544568 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b544568\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b54537c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b54537c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b9c1f14 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b9c1f14\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b9c335e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0b9c335e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ba83e95 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0ba83e95\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb42dc3 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb42dc3\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb4558e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb4558e\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb4869c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bb4869c\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bbf09a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bbf09a0\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bc84816 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bc84816\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bd456a7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bd456a7\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bfadbfc 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_0bfadbfc\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0aa291f2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0aa291f2\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0af2b5f5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0af2b5f5\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0b22a42a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0b22a42a\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0b8f09a0 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0b8f09a0\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0ba29848 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0ba29848\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0bde404a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8641507c7a44a176ab94a9e6e2adf59641fb8c1_0bde404a\Report.wer 2486 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0652c438 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0652c438\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0944822a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_8adc3cc7104539f37be4abea5e2610847e1534_0944822a\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_042c186f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_042c186f\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0adc8601 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_25a8e9cd78cd7168f27ac4fe734b43542c377844_0adc8601\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d978e367ac2bba9eecd773aec079879f49549_084d4fb6 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d978e367ac2bba9eecd773aec079879f49549_084d4fb6\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_dc154660d88ba4bf5b21262b353aff6ef05a83a2_0e3a52b1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_dc154660d88ba4bf5b21262b353aff6ef05a83a2_0e3a52b1\Report.wer 2484 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_dd55cb1f5b8cf75fe6c6605411d24773e0cd1929_05964fc5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_dd55cb1f5b8cf75fe6c6605411d24773e0cd1929_05964fc5\Report.wer 3398 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_def1598a3da27415a090a4f0f9a9ff21113e62fa_0dca4172 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_def1598a3da27415a090a4f0f9a9ff21113e62fa_0dca4172\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e42ed07bf1985fd95f5ed970fd74bdb71d9aee2_099b14a9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e42ed07bf1985fd95f5ed970fd74bdb71d9aee2_099b14a9\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e42ed07bf1985fd95f5ed970fd74bdb71d9aee2_0bf7c86d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e42ed07bf1985fd95f5ed970fd74bdb71d9aee2_0bf7c86d\Report.wer 2510 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e496e3855337e91b37eca02b428ac5199de7_0a703b5b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e496e3855337e91b37eca02b428ac5199de7_0a703b5b\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e4beb524713e562b08ff453859ada06f4f9c58_09b84401 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e4beb524713e562b08ff453859ada06f4f9c58_09b84401\Report.wer 2496 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e6148a993d8a179a09e8d8f5f4144dfdb467e5c_088d0c03 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e6148a993d8a179a09e8d8f5f4144dfdb467e5c_088d0c03\Report.wer 2504 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e6943f3f0c315312aa7415b2f5389d05668a43a_0aace262 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_e6943f3f0c315312aa7415b2f5389d05668a43a_0aace262\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_eb48fe9f6a64abae606bf3673282e68394076_181771f7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_eb48fe9f6a64abae606bf3673282e68394076_181771f7\Report.wer 2502 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_edb32fcda8bfb3f293cc789af0f0f47f13d13050_136f7e65 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_edb32fcda8bfb3f293cc789af0f0f47f13d13050_136f7e65\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_03237992 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_03237992\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_04fe730d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_f2ac31cea47a3ff83385a5ee930a4753d94347_04fe730d\Report.wer 2492 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a9c3e95 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a9c3e95\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a9df7e5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a9df7e5\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aaa697b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aaa697b\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aaa75cb 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aaa75cb\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ab44eda 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ab44eda\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ab5b21f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ab5b21f\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aba1506 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0aba1506\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0abc869c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0abc869c\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac2d316 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac2d316\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac3708d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac3708d\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac85697 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0ac85697\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0be6b50b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0be6b50b\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0beb2f68 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0beb2f68\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0bf231b9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0bf231b9\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0c62e7fd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0c62e7fd\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0d37e906 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0d37e906\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0d7de0ad 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0d7de0ad\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0deb7751 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0deb7751\Report.wer 1812 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_00958595 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_00958595\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_04f8d3d2 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_04f8d3d2\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_06f1e049 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_d91c89e6616e815cfbcacc751a183a7c9cd46_06f1e049\Report.wer 2206 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_1b516aab 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_1b516aab\Report.wer 2498 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccd0ef4dcbc4c442f2a8f74dff47c1b0913c12_0a3b0482 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccd0ef4dcbc4c442f2a8f74dff47c1b0913c12_0a3b0482\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccefaa4146ce6436e6ac15aa452cdeab18e13_0f12a17e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_ccefaa4146ce6436e6ac15aa452cdeab18e13_0f12a17e\Report.wer 2506 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_cde56e6c0138551a075c5aa701eca754b65e6e_0aee739a 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_cde56e6c0138551a075c5aa701eca754b65e6e_0aee739a\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d0c8e6b891f57490ca3febe7618f98d2d14b3ae_0d3d2cad 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d0c8e6b891f57490ca3febe7618f98d2d14b3ae_0d3d2cad\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d234ab424757e6f6a5d2a894c5b0a822a32e84_0f0a6e3d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d234ab424757e6f6a5d2a894c5b0a822a32e84_0f0a6e3d\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_03c8fc78 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_03c8fc78\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_087c9903 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_087c9903\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_0bcadb12 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_0bcadb12\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_0d219406 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d3cf4e37a6f3d885fa42686fc83262f78cf7cd1f_0d219406\Report.wer 2490 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_0b9d9c9c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_0b9d9c9c\Report.wer 2500 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_0b1acb97 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_0b1acb97\Report.wer 2508 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ccb12020f4e8a356aa6bab1b463e844a8c236365_cab_0a3a335e\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_16de1ac0319dd0479fb9c0bc2a5895fe2ae5724_cab_1aec1808\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_281e8d1f2f9881cbbccc2d35bf6771d1c283abd_cab_1a7e3d30\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_2e49557b54d33edd735504ac9142d7219d9bb5_cab_0f0795fa\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_323ace746bdfaed25e6fe3bfd73cef46e77d5a5_cab_08a1083b\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_345d282f1e8faf2512daadfa897173c92787527_cab_0fd4b388\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_34dcc3fc46cf51f60f9968656ca1c2648140_cab_0b30a4f5\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_4053cf7e5e5acbbc5f444b21e49096d85776f2e4_cab_0b48032b\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_6a2ebce759e32b78518db62d497343c01caf65_cab_0462c32f\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c76e8110ca442bcc36d2d827ca51fc163dd4fe_cab_0b66235b\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d41a8f99d0e93a5669d0ab6ee6d7765e13daeae_cab_09b2e3b9\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0e0d080c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0e0d080c\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_153abc7b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_153abc7b\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_52c81b088d545d5edacaeb3aec34b2ffd2337b3_cab_07917520\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_69a32e1dd7ad392d51bd17da08cc6a26b887df_cab_0c23ae88\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_79a8488dae76c0e733e844d668e5892de61d7851_cab_0d08dc3d\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_89f5f5975e371cb950259593ec131ddd91ecac3_cab_0bc01132\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_8a992de2c32f2c213ed0ea861c4a48e58fc5b44_cab_094f4182\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_9536573ccd9797de236861fda4a18dde745ccaa5_cab_054dd02b\CbsPersist_20160211075000.log 440739855 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CBS.log 440547688 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\poqexec.log 37755 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\Report.wer 48438 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\Sessions.xml 7762252 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a2777015b036a0b414b1fdfe7eb0a6caa233159_cab_0471b28d\setupapi.dev.log 122777 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a322da3820c3be91a3fc78e59f24f6a633ce90f1_cab_0a5e4337\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a519d392a74c9af02a1d12e14ea1b937b3b5b5_cab_083c4e8f\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_a5af4a17c3235fa979d839aca13ec15661ea_cab_1ac22477\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_ac74b022dbaf2457e2431a4edaef8296f59438fe_cab_09fc4e6d\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_afcbb095936372daf1337f76c18b6cb8557fe2_cab_067c04d1\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_b8a2d4944efe9b338bbf68cc3f07e74129ef124_cab_03ed6c87\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160211075000.log 440739855 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CBS.log 11283539 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160213080516.log 1765316197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160213105307.log 1083819303 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160214101205.log 404452033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160227093807.log 209810349 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160310101109.log 1655590467 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160327091221.log 514437121 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160328091356.log 143162291 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\CbsPersist_20160416120233.log -1767909888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\poqexec.log 40365 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\Report.wer 50808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\Sessions.xml 8170306 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_bdf5342d5cb65079aee6f8662f8350d13a55667_cab_184a66de\setupapi.dev.log 122777 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_c31454441fa165bbc913d8b630fb7058787768f_cab_0a2a8861\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_155ce6bd 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_155ce6bd\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_164e2d09 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_164e2d09\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_17b65c1b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_17b65c1b\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_19c716c4 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_19c716c4\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a9faf95 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_1a9faf95\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_cab_0ff8212d\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a33361c 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0a33361c\Report.wer 1420 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0f33bfc5 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_0f33bfc5\Report.wer 1420 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_ae2084dde82277d6cba463e2d72bfaa678d377_cab_0a039693\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_f12040a98ca447b913fd2d9bd850395921d493_cab_1b25612b\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_3c5482ab416cca01c78389dfcebacdd7914e_cab_04da2e9f\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_d43193ec180388c7cfd4069fe59a8edb82d2ff5_cab_0b2a14b8\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CBS.log 440552122 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\poqexec.log 37755 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\Report.wer 48434 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\Sessions.xml 7762252 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_f3a67f4a41c2db6567909c32b98cb1fd4ce2ef_cab_02a88363\setupapi.dev.log 122777 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CBS.log 440554562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\poqexec.log 37755 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\Report.wer 48438 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\Sessions.xml 7762252 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601.18766_fd86346786f4b248dcc22593892a9951c79b79a6_cab_0951e773\setupapi.dev.log 122777 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150708185732.log 254179072 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150710214706.log 135635627 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150718130301.log 1362582520 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150728094315.log -257334922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150729185430.log 222249143 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150731202607.log 270846473 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150801162541.log 135345293 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150801191210.log 134614687 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150803204917.log 270685969 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150805202528.log 270832932 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150809084809.log 542237992 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150810202314.log 270224947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150811193225.log 135494022 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150816142414.log 489471745 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150818192251.log 515580766 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150822192029.log 607299760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150910170354.log 439542098 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151009164851.log 190825100 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151009190656.log 175825258 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151010124901.log 175092116 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151010151929.log 175824536 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151010173550.log 175092368 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151010185701.log 175086888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151011102245.log 175086887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151011190448.log 175824705 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151012170934.log 175087216 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150707190823.log 128781711 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150815194142.log -1737273947 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151013140140.log 175825019 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151219120712.log 197914454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151224182337.log 192845357 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151230113043.log 192014422 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160107163746.log 192844519 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160211075000.log 440739855 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151013173152.log 175846037 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151014140537.log 174959029 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151014170326.log 770751724 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151014182957.log 185620257 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151015062823.log 185619789 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151015170523.log 185626373 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151015182220.log 186349404 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151017154903.log 786101963 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151018101237.log 186436737 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151111221319.log 526008010 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151112115057.log 191264772 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151112194014.log 194134234 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151209201241.log 220051265 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151219185211.log 192061195 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151219201617.log 192061372 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151220113117.log 192061548 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151220200019.log 192795197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151220202953.log 192020083 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151221183530.log 192850033 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151221194828.log 192061350 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151222104246.log 192061469 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151222181319.log 192794642 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151222202849.log 192014922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151223182652.log 192814142 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151224074116.log 192106125 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151224120223.log 192014272 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151224201932.log 192055761 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151225113437.log 192056130 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151225181830.log 192805011 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151225213954.log 192020336 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151226154459.log 192845808 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151226182712.log 192056049 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151226204049.log 192061428 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151227113104.log 192061248 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151227191144.log 192794540 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151228115051.log 192065226 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151228194736.log 192489092 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151229110445.log 192081929 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151230110322.log 192795247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CBS.log 200904008 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150617190242.cab 77946491 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150620152221.cab 66871235 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150622215600.cab 98952707 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150623142051.cab 53921247 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150627125227.cab 119199446 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150706144041.log -1452045170 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150706190747.log 163811826 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20150707072805.log 94981308 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151231112000.log 192839887 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20151231205948.log 192794334 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160101112223.log 192055846 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160102112752.log 192793949 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160103114000.log 192793922 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160103160237.log 192787888 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160103200440.log 192060440 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160104112208.log 192060261 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160105115916.log 192788448 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160105182111.log 192787760 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160105195052.log 192055091 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160106130208.log 192055053 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160106185425.log 192752551 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160107202955.log 192106571 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160108123037.log 192060120 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160109115654.log 192794245 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160109191542.log 193786454 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160110115057.log 192764715 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160110180605.log 192752913 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160111102415.log 192047065 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160111154659.log 192793940 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160111183108.log 192061001 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160112104714.log 192060898 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160112135926.log 192789097 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160113013441.log 192023562 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160115201810.log 1159559285 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160213080516.log 1765316197 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\CbsPersist_20160213105307.log 1083819303 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\FilterList.log 444 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\poqexec.log 38613 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\Report.wer 50376 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\SCM.EVM 425984 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\Sessions.xml 7895876 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\WER4BCE.tmp.hdmp 51541987 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_15abc8523f393efefadc99f43b9348d62fe4e8b_cab_14215927\WER57E0.tmp.mdmp 987837 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0b05a7b7 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0b05a7b7\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0c1cc382 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0c1cc382\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0fe01fa8 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_0fe01fa8\Report.wer 1748 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_12ce1885 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_12ce1885\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_14850a62 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_14850a62\Report.wer 1810 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_14974339 0 bytes File C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7601_605e27ec7c6543a12cb1701baa42b6df4e6a93_14974339\Report.wer 1748 bytes File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863} 0 bytes File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpasbase.vdm 11628944 bytes executable File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpasdlta.vdm 339344 bytes executable File C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D2B0B133-42ED-44D3-809A-46EBB62BA863}\mpengine.dll 8199504 bytes executable File C:\ProgramData\NVIDIA\Updatus