Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

keyboard and input Lag in Games, not sure if infected


  • Please log in to reply
4 replies to this topic

#1 Colouras

Colouras

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:01 AM

Posted 28 June 2014 - 06:08 PM

i was searching on the web for fixes for my sudden slow down and crackling during games i was playing, i deleted the ATA/ ATAPI controllers to fix the problem. the crackling and slow down was fixed but my keyboard and mouse input would lag every so often. (I have recently also reformatted my computer as not too long ago as well)

 

I've seen a old post about this and I've downloaded GMER and have already scanned my computer

 

GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-06-28 16:06:14
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST975042 rev.0002 698.64GB
Running: 7jilxgwy.exe; Driver: C:\Users\TULE~1\AppData\Local\Temp\pxldipow.sys
 
 
---- Kernel code sections - GMER 2.1 ----
 
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                                      fffff800031ba000 65 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594                                                                                      fffff800031ba042 4 bytes [00, 00, 00, 00]
 
---- User code sections - GMER 2.1 ----
 
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!RegSetValueExW                                          0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                        0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                         0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                   0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                 0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                 0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\kernel32.dll!RegSetValueExA                                          0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                       0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                       0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\USER32.dll!CreateWindowExW                                           0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                  0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\ole32.dll!CoCreateInstance                                           000007fefdae7490 11 bytes JMP 000007fffce90228
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1176] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                          000007fefdafbf00 7 bytes JMP 000007fffce90260
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                       0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                     0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                      0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                              0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                              0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                       0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                        000007fefcea2db0 5 bytes JMP 000007fffce90180
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                   000007fefcea37d0 7 bytes JMP 000007fffce900d8
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                     000007fefcea8ef0 6 bytes JMP 000007fffce90148
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                 000007fefcebaf60 5 bytes JMP 000007fffce90110
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                  000007feff1c89e0 8 bytes JMP 000007fffce901f0
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                000007feff1cbe40 8 bytes JMP 000007fffce901b8
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                                    0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                                    0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\USER32.dll!CreateWindowExW                                                                        0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                             0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                               0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                                                        000007fef5e7dc88 5 bytes JMP 000007fff5c700d8
.text     C:\Windows\system32\Dwm.exe[2712] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                                                       000007fef5e7de10 5 bytes JMP 000007fff5c70110
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                   0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                 0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                  0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                            0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                          0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                          0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                   0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                                0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                                0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\USER32.dll!CreateWindowExW                                                                    0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                         0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\system32\taskeng.exe[3092] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                           0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                              0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                            0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                             0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                       0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                     0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                     0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                              0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                           0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                           0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\USER32.dll!CreateWindowExW                                                               0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                    0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\P4G\BatteryLife.exe[3292] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                      0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                   0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                 0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                  0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                            0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                          0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                          0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                   0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                                0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                                0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\USER32.dll!CreateWindowExW                                                                    0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                         0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\system32\taskeng.exe[3312] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                           0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                    0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                  0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                   0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                             0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                           0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                           0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                    0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                 0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                 0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\USER32.dll!CreateWindowExW                                                     0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files (x86)\ASUS\Splendid\ACMON.exe[3468] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                            0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                  0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                 0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                           0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                         0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                         0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                  0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                               0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                               0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\USER32.dll!CreateWindowExW                                                                   0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\SysWOW64\ACEngSvr.exe[3548] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                          0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                  0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                 0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                           0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                         0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                         0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                  0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                               0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                               0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\USER32.dll!CreateWindowExW                                                                   0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\System32\igfxpers.exe[3816] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                          0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!RegSetValueExW                                            0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                          0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                           0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                     0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                   0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                   0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\kernel32.dll!RegSetValueExA                                            0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                         0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                         0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\USER32.dll!CreateWindowExW                                             0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                  0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe[3860] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                    0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                    0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                  0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                   0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                             0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                           0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                           0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                    0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                 0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                 0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\USER32.dll!CreateWindowExW                                                     0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4048] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                            0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!RegSetValueExW                                   0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                 0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                  0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                            0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                          0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                          0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\kernel32.dll!RegSetValueExA                                   0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\USER32.dll!CreateWindowExW                                    0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                         0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4056] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                           0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                             0000000076281f0e 7 bytes JMP 0000000174583df0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                               0000000076285bad 7 bytes JMP 0000000174584100
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                               0000000076291409 7 bytes JMP 0000000174583f30
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                              000000007629ea45 7 bytes JMP 0000000174583de0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                      0000000076328e24 7 bytes JMP 0000000174583b50
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                      0000000076328ea9 5 bytes JMP 0000000174583c00
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                        00000000763291ff 5 bytes JMP 0000000174583b60
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                           0000000076ad1d29 5 bytes JMP 0000000174583ae0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                         0000000076ad1dd7 5 bytes JMP 0000000174583a90
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                             0000000076ad2ab1 5 bytes JMP 0000000174583c10
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                0000000076ad2d17 5 bytes JMP 0000000174583870
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                0000000076d38a29 5 bytes JMP 0000000174583350
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                            0000000076d44572 5 bytes JMP 00000001745837f0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                            0000000076d5e567 5 bytes JMP 0000000174583860
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                       0000000076d807d7 5 bytes JMP 0000000174583280
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                     0000000076d97a5c 5 bytes JMP 00000001745837e0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                        0000000074cbe96b 5 bytes JMP 00000001745833c0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                          0000000074cbeba5 5 bytes JMP 00000001745833d0
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                               00000000768d5ea5 5 bytes JMP 0000000174583300
.text     C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4076] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                0000000076909d0b 5 bytes JMP 0000000174583290
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                             0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                           0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                            0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                      0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                    0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                    0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                             0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                          0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                          0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\USER32.dll!CreateWindowExW                                                              0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                                   0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Windows\system32\wbem\unsecapp.exe[4284] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                                     0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!RegSetValueExW                                   0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                 0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                  0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                            0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                          0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                          0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\kernel32.dll!RegSetValueExA                                   0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\USER32.dll!CreateWindowExW                                    0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                         0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4504] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                           0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                    0000000076281f0e 7 bytes JMP 0000000174583df0
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                      0000000076285bad 7 bytes JMP 0000000174584100
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                      0000000076291409 7 bytes JMP 0000000174583f30
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                     000000007629ea45 7 bytes JMP 0000000174583de0
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                             0000000076328e24 7 bytes JMP 0000000174583b50
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                             0000000076328ea9 5 bytes JMP 0000000174583c00
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                               00000000763291ff 5 bytes JMP 0000000174583b60
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                  0000000076ad1d29 5 bytes JMP 0000000174583ae0
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                0000000076ad1dd7 5 bytes JMP 0000000174583a90
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                    0000000076ad2ab1 5 bytes JMP 0000000174583c10
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                       0000000076ad2d17 5 bytes JMP 0000000174583870
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                       0000000076d38a29 5 bytes JMP 0000000174583350
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                   0000000076d44572 5 bytes JMP 00000001745837f0
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                   0000000076d5e567 5 bytes JMP 0000000174583860
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                              0000000076d807d7 5 bytes JMP 0000000174583280
.text     C:\Program Files (x86)\Skype\Phone\Skype.exe[5480] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                            0000000076d97a5c 5 bytes JMP 00000001745837e0
.text     C:\Program Files (x86)\Gyazo\GyStation.exe[5488] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                         0000000076d38a29 5 bytes JMP 0000000174583350
.text     C:\Program Files (x86)\Gyazo\GyStation.exe[5488] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                     0000000076d44572 5 bytes JMP 00000001745837f0
.text     C:\Program Files (x86)\Gyazo\GyStation.exe[5488] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                     0000000076d5e567 5 bytes JMP 0000000174583860
.text     C:\Program Files (x86)\Gyazo\GyStation.exe[5488] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                0000000076d807d7 5 bytes JMP 0000000174583280
.text     C:\Program Files (x86)\Gyazo\GyStation.exe[5488] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                              0000000076d97a5c 5 bytes JMP 00000001745837e0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!RegSetValueExW                                            0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                          0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                           0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                     0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                   0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                   0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\kernel32.dll!RegSetValueExA                                            0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                         0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                         0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\USER32.dll!CreateWindowExW                                             0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                  0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5544] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                    0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!RegSetValueExW                                     0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                   0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                    0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                              0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                            0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                            0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\kernel32.dll!RegSetValueExA                                     0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                  0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                  0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\USER32.dll!CreateWindowExW                                      0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                           0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe[5748] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                             0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                              0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                               0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                         0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                       0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                       0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                             0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                             0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\USER32.dll!CreateWindowExW                                                 0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                      0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[5780] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                        0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                    0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                  0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                   0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                             0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                           0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                           0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                    0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                 0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                 0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\USER32.dll!CreateWindowExW                                                     0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[5936] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                            0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                 0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                               0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                          0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                        0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                        0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                 0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                              0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                              0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\USER32.dll!CreateWindowExW                                                  0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                       0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[5976] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                         0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                   0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                 0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                  0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                            0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                          0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                          0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                   0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                                0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                                0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\USER32.dll!CreateWindowExW                                                    0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                                         0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW                                           0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\ole32.dll!CoCreateInstance                                                    000007fefdae7490 11 bytes JMP 000007fffce90228
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[6072] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                   000007fefdafbf00 7 bytes JMP 000007fffce90260
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!RegSetValueExW            0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!RegQueryValueExW          0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!RegDeleteValueW           0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW     0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx   0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!K32GetModuleInformation   0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\kernel32.dll!RegSetValueExA            0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW         0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA         0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\USER32.dll!CreateWindowExW             0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo  0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe[5712] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW    0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                            0000000076281f0e 7 bytes JMP 0000000174583df0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                              0000000076285bad 7 bytes JMP 0000000174584100
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                              0000000076291409 7 bytes JMP 0000000174583f30
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                             000000007629ea45 7 bytes JMP 0000000174583de0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                     0000000076328e24 7 bytes JMP 0000000174583b50
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                     0000000076328ea9 5 bytes JMP 0000000174583c00
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                       00000000763291ff 5 bytes JMP 0000000174583b60
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                          0000000076ad1d29 5 bytes JMP 0000000174583ae0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                        0000000076ad1dd7 5 bytes JMP 0000000174583a90
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                            0000000076ad2ab1 5 bytes JMP 0000000174583c10
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                               0000000076ad2d17 5 bytes JMP 0000000174583870
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                               0000000076d38a29 5 bytes JMP 0000000174583350
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                           0000000076d44572 5 bytes JMP 00000001745837f0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                           0000000076d5e567 5 bytes JMP 0000000174583860
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                      0000000076d807d7 5 bytes JMP 0000000174583280
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                    0000000076d97a5c 5 bytes JMP 00000001745837e0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                       0000000074cbe96b 5 bytes JMP 00000001745833c0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                         0000000074cbeba5 5 bytes JMP 00000001745833d0
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                              00000000768d5ea5 5 bytes JMP 0000000174583300
.text     C:\Windows\WebCam\S6000\S6000Mnt.exe[6432] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                               0000000076909d0b 5 bytes JMP 0000000174583290
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!RegSetValueExW                       0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!RegQueryValueExW                     0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!RegDeleteValueW                      0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx              0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!K32GetModuleInformation              0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\kernel32.dll!RegSetValueExA                       0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                    0000000076f46c80 5 bytes JMP 000000016fff02d0
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                    0000000076f4a5b4 5 bytes JMP 000000016fff0298
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\USER32.dll!CreateWindowExW                        0000000076f50810 7 bytes JMP 000000016fff0308
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo             0000000076f5ccec 9 bytes JMP 000000016fff0260
.text     C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[6304] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW               0000000076f90700 5 bytes JMP 000000016fff0340
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                          0000000076281f0e 7 bytes JMP 0000000174583df0
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                            0000000076285bad 7 bytes JMP 0000000174584100
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                            0000000076291409 7 bytes JMP 0000000174583f30
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                           000000007629ea45 7 bytes JMP 0000000174583de0
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                   0000000076328e24 7 bytes JMP 0000000174583b50
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                   0000000076328ea9 5 bytes JMP 0000000174583c00
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                     00000000763291ff 5 bytes JMP 0000000174583b60
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                        0000000076ad1d29 5 bytes JMP 0000000174583ae0
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                      0000000076ad1dd7 5 bytes JMP 0000000174583a90
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                          0000000076ad2ab1 5 bytes JMP 0000000174583c10
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                             0000000076ad2d17 5 bytes JMP 0000000174583870
.text     C:\Program Files (x86)\Steam\Steam.exe[2160] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate                                                              0000000076ad54a9 5 bytes JMP 0000000100190800
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322                                                                 0000000074781a22 2 bytes [78, 74]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496                                                                 0000000074781ad0 2 bytes [78, 74]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552                                                                 0000000074781b08 2 bytes [78, 74]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730                                                                 0000000074781bba 2 bytes [78, 74]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762                                                                 0000000074781bda 2 bytes [78, 74]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                                                          0000000076a71465 2 bytes [A7, 76]
.text     C:\Windows\SysWOW64\PnkBstrB.exe[1388] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                                                         0000000076a714bb 2 bytes [A7, 76]
.text     ...                                                                                                                                                     * 2
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!RegSetValueExW                                            0000000076e2a400 7 bytes JMP 000000016fff0228
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                          0000000076e33f20 5 bytes JMP 000000016fff0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                           0000000076e4ffb0 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                     0000000076e5f2e0 5 bytes JMP 000000016fff0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                   0000000076e89a30 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                   0000000076e994c0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\kernel32.dll!RegSetValueExA                                            0000000076eb87e0 7 bytes JMP 000000016fff01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                             000007fefcea2db0 5 bytes JMP 000007fffce90180
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                        000007fefcea37d0 7 bytes JMP 000007fffce900d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                          000007fefcea8ef0 6 bytes JMP 000007fffce90148
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                      000007fefcebaf60 5 bytes JMP 000007fffce90110
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                       000007feff1c89e0 8 bytes JMP 000007fffce901f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6860] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                     000007feff1cbe40 8 bytes JMP 000007fffce901b8
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                            0000000076281f0e 7 bytes JMP 0000000174583df0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                              0000000076285bad 7 bytes JMP 0000000174584100
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                              0000000076291409 7 bytes JMP 0000000174583f30
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                             000000007629ea45 7 bytes JMP 0000000174583de0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                     0000000076328e24 7 bytes JMP 0000000174583b50
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                     0000000076328ea9 5 bytes JMP 0000000174583c00
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                       00000000763291ff 5 bytes JMP 0000000174583b60
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                          0000000076ad1d29 5 bytes JMP 0000000174583ae0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                        0000000076ad1dd7 5 bytes JMP 0000000174583a90
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                            0000000076ad2ab1 5 bytes JMP 0000000174583c10
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                               0000000076ad2d17 5 bytes JMP 0000000174583870
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                       0000000074cbe96b 5 bytes JMP 00000001745833c0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                         0000000074cbeba5 5 bytes JMP 00000001745833d0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                               0000000076d38a29 5 bytes JMP 0000000174583350
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                           0000000076d44572 5 bytes JMP 00000001745837f0
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                           0000000076d5e567 5 bytes JMP 0000000174583860
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                      0000000076d807d7 5 bytes JMP 0000000174583280
.text     C:\Users\Tu LE\Downloads\7jilxgwy.exe[156] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                    0000000076d97a5c 5 bytes JMP 00000001745837e0
---- Processes - GMER 2.1 ----
 
Process   C:\ExpressGateUtil\VAWinService.exe (*** suspicious ***) @ C:\ExpressGateUtil\VAWinService.exe [2316](2010-08-21 01:47:58)                              0000000000950000
Library   C:\ExpressGateUtil\libexpat.dll (*** suspicious ***) @ C:\ExpressGateUtil\VAWinService.exe [2316](2010-08-13 00:52:16)                                  0000000010000000
Library   C:\ExpressGateUtil\netProfileDatabase.DLL (*** suspicious ***) @ C:\ExpressGateUtil\VAWinService.exe [2316](2010-08-13 00:52:16)                        00000000746a0000
Process   C:\ExpressGateUtil\VAWinAgent.exe (*** suspicious ***) @ C:\ExpressGateUtil\VAWinAgent.exe [6492](2010-08-13 00:52:16)                                  0000000000c20000
 
---- Registry - GMER 2.1 ----
 
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\485d6021838a                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06df1a5a8                                                                             
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\485d6021838a (not active ControlSet)                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06df1a5a8 (not active ControlSet)                                                         
 
---- EOF - GMER 2.1 ----
 


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:01 PM

Posted 03 July 2014 - 06:10 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/539351 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Colouras

Colouras
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:01 AM

Posted 03 July 2014 - 10:49 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.
 

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/539351 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

 

 

 

Attached Files


Edited by Colouras, 03 July 2014 - 10:50 PM.


#4 Colouras

Colouras
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:01 AM

Posted 03 July 2014 - 10:57 PM

I'm Running on windows 7 64 and i've recently Reformatted this computer about 2 weeks back. I wanted to clear the clutter and get more space. I've re-installed games but i've noticed that there has been a occasional slow down and then the audio crackling (which still happens but not as often after i deleted the ATA/atapi controller drvers) After i tried removing those controller drivers, i began noticing a slight input delay on my mouse and keyboard on some games.

 I am not sure if my computer may be just having performance issues or if something in it is corrupted, or i may be even infected even after Reformatting (which i do not know if its possible or not) 

 

 I would be happy to have some clarification and help to ease the worry of possible information or banking stuff being invaded 



#5 nasdaq

nasdaq

  • Malware Response Team
  • 39,586 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:12:01 PM

Posted 05 July 2014 - 07:13 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download Malwarebytes' Anti-Malware from Here

Double-click mbam-setup-2.X.X.XXXX.exe to install the application (X's are the current version number).
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once MBAM opens, when it says Your databases are out of date, click the Fix Now button.
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click the Scan Now button.
  • If you receive a message that updates are available, click the Update Now button (the update will be downloaded, installed, and the scan will start).
  • The scan may take some time to finish,so please be patient.
  • If potential threats are detected, ensure that Quarantine is selected as the Action for all the listed items, and click the Apply Actions button.
  • While still on the Scan tab, click the link for View detailed log, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log is automatically saved by MBAM and can also be viewed by clicking the History tab and then selecting Application Logs.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.

===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Download the correct version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.
To attach a file select the "More Reply Option" and follow the instructions.

Let me know what problem persists.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users