.text C:\Program Files\DellTPad\Apoint.exe[4100] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Program Files\DellTPad\Apoint.exe[4100] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Program Files\DellTPad\Apoint.exe[4100] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Windows\System32\igfxpers.exe[4124] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Windows\System32\igfxpers.exe[4124] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Windows\System32\igfxpers.exe[4124] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077a43ae0 6 bytes {JMP QWORD [RIP+0x85fc550]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077a71400 6 bytes {JMP QWORD [RIP+0x85aec30]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077a715d0 6 bytes {JMP QWORD [RIP+0x874ea60]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077a71640 6 bytes {JMP QWORD [RIP+0x882e9f0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077a71680 6 bytes {JMP QWORD [RIP+0x87ee9b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077a71720 6 bytes {JMP QWORD [RIP+0x884e910]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077a717b0 6 bytes {JMP QWORD [RIP+0x87ce880]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077a717f0 6 bytes {JMP QWORD [RIP+0x86ce840]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077a71840 6 bytes {JMP QWORD [RIP+0x86ee7f0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077a71860 6 bytes {JMP QWORD [RIP+0x880e7d0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort 0000000077a71a50 6 bytes {JMP QWORD [RIP+0x88ce5e0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077a71b60 6 bytes {JMP QWORD [RIP+0x86ae4d0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort 0000000077a71c30 6 bytes {JMP QWORD [RIP+0x876e400]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a71d80 6 bytes {JMP QWORD [RIP+0x886e2b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077a71d90 6 bytes {JMP QWORD [RIP+0x88ae2a0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077a72100 6 bytes {JMP QWORD [RIP+0x878df30]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 0000000077a72190 6 bytes {JMP QWORD [RIP+0x888dea0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077a72a00 6 bytes {JMP QWORD [RIP+0x87ad630]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077a72a80 6 bytes {JMP QWORD [RIP+0x870d5b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077a72b00 6 bytes {JMP QWORD [RIP+0x872d530]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\GDI32.dll!DeleteDC 000007feff7422cc 6 bytes {JMP QWORD [RIP+0x64dd64]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\GDI32.dll!CreateDCW 000007feff748398 6 bytes {JMP QWORD [RIP+0x4a7c98]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\GDI32.dll!CreateDCA 000007feff7489c8 6 bytes {JMP QWORD [RIP+0x487668]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1436] C:\Windows\system32\GDI32.dll!GetPixel 000007feff749344 6 bytes {JMP QWORD [RIP+0x626cec]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077a43ae0 6 bytes {JMP QWORD [RIP+0x85fc550]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077a71400 6 bytes {JMP QWORD [RIP+0x85aec30]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077a715d0 6 bytes {JMP QWORD [RIP+0x874ea60]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077a71640 6 bytes {JMP QWORD [RIP+0x882e9f0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077a71680 6 bytes {JMP QWORD [RIP+0x87ee9b0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077a71720 6 bytes {JMP QWORD [RIP+0x884e910]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077a717b0 6 bytes {JMP QWORD [RIP+0x87ce880]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077a717f0 6 bytes {JMP QWORD [RIP+0x86ce840]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077a71840 6 bytes {JMP QWORD [RIP+0x86ee7f0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077a71860 6 bytes {JMP QWORD [RIP+0x880e7d0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort 0000000077a71a50 6 bytes {JMP QWORD [RIP+0x88ce5e0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077a71b60 6 bytes {JMP QWORD [RIP+0x86ae4d0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort 0000000077a71c30 6 bytes {JMP QWORD [RIP+0x876e400]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a71d80 6 bytes {JMP QWORD [RIP+0x886e2b0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077a71d90 6 bytes {JMP QWORD [RIP+0x88ae2a0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077a72100 6 bytes {JMP QWORD [RIP+0x878df30]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 0000000077a72190 6 bytes {JMP QWORD [RIP+0x888dea0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077a72a00 6 bytes {JMP QWORD [RIP+0x87ad630]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077a72a80 6 bytes {JMP QWORD [RIP+0x870d5b0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077a72b00 6 bytes {JMP QWORD [RIP+0x872d530]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\GDI32.dll!DeleteDC 000007feff7422cc 6 bytes {JMP QWORD [RIP+0x64dd64]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\GDI32.dll!CreateDCW 000007feff748398 6 bytes {JMP QWORD [RIP+0x4a7c98]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\GDI32.dll!CreateDCA 000007feff7489c8 6 bytes {JMP QWORD [RIP+0x487668]}
.text C:\Windows\system32\SearchIndexer.exe[4516] C:\Windows\system32\GDI32.dll!GetPixel 000007feff749344 6 bytes {JMP QWORD [RIP+0x626cec]}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2032] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2032] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2032] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2032] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2032] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtClose 0000000077c1f9c0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4 0000000077c1f9c4 2 bytes [AE, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077c1fc90 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4 0000000077c1fc94 2 bytes [6B, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c1fd44 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c1fd48 2 bytes [56, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection 0000000077c1fda8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4 0000000077c1fdac 2 bytes [5C, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken 0000000077c1fea0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4 0000000077c1fea4 2 bytes [53, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c1ff84 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c1ff88 2 bytes [5F, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077c1ffe4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4 0000000077c1ffe8 2 bytes [77, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077c20064 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4 0000000077c20068 2 bytes [74, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077c20094 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077c20098 2 bytes [59, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort 0000000077c20398 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4 0000000077c2039c 2 bytes [47, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c20530 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4 0000000077c20534 2 bytes [7A, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort 0000000077c20674 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4 0000000077c20678 2 bytes [68, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077c2086c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077c20870 2 bytes [50, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077c20884 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4 0000000077c20888 2 bytes [4A, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077c20dd4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4 0000000077c20dd8 2 bytes [65, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject 0000000077c20eb8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4 0000000077c20ebc 2 bytes [4D, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077c21bc4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4 0000000077c21bc8 2 bytes [62, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem 0000000077c21c94 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4 0000000077c21c98 2 bytes [71, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077c21d6c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4 0000000077c21d70 2 bytes [6E, 71]
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077c41217 6 bytes {JMP QWORD [RIP+0x71a7001e]}
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007720103d 6 bytes {JMP QWORD [RIP+0x719b001e]}
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000077201072 6 bytes {JMP QWORD [RIP+0x7198001e]}
.text C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe[5288] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW 000000007722c9b5 6 bytes {JMP QWORD [RIP+0x7192001e]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077a43ae0 6 bytes {JMP QWORD [RIP+0x85fc550]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077a71400 6 bytes {JMP QWORD [RIP+0x85aec30]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077a715d0 6 bytes {JMP QWORD [RIP+0x874ea60]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077a71640 6 bytes {JMP QWORD [RIP+0x882e9f0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077a71680 6 bytes {JMP QWORD [RIP+0x87ee9b0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077a71720 6 bytes {JMP QWORD [RIP+0x884e910]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077a717b0 6 bytes {JMP QWORD [RIP+0x87ce880]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077a717f0 6 bytes {JMP QWORD [RIP+0x86ce840]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077a71840 6 bytes {JMP QWORD [RIP+0x86ee7f0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077a71860 6 bytes {JMP QWORD [RIP+0x880e7d0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort 0000000077a71a50 6 bytes {JMP QWORD [RIP+0x88ce5e0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077a71b60 6 bytes {JMP QWORD [RIP+0x86ae4d0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort 0000000077a71c30 6 bytes {JMP QWORD [RIP+0x876e400]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a71d80 6 bytes {JMP QWORD [RIP+0x886e2b0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077a71d90 6 bytes {JMP QWORD [RIP+0x88ae2a0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077a72100 6 bytes {JMP QWORD [RIP+0x878df30]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 0000000077a72190 6 bytes {JMP QWORD [RIP+0x888dea0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077a72a00 6 bytes {JMP QWORD [RIP+0x87ad630]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077a72a80 6 bytes {JMP QWORD [RIP+0x870d5b0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077a72b00 6 bytes {JMP QWORD [RIP+0x872d530]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW 000000007755a420 6 bytes {JMP QWORD [RIP+0x8b45c10]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\system32\kernel32.dll!CreateProcessW 0000000077571b50 6 bytes {JMP QWORD [RIP+0x8aee4e0]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\system32\kernel32.dll!CreateProcessA 00000000775e8810 6 bytes {JMP QWORD [RIP+0x8a97820]}
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Windows\system32\svchost.exe[5620] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077a43ae0 6 bytes {JMP QWORD [RIP+0x85fc550]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077a71400 6 bytes {JMP QWORD [RIP+0x85aec30]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077a715d0 6 bytes {JMP QWORD [RIP+0x874ea60]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077a71640 6 bytes {JMP QWORD [RIP+0x882e9f0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077a71680 6 bytes {JMP QWORD [RIP+0x87ee9b0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077a71720 6 bytes {JMP QWORD [RIP+0x884e910]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077a717b0 6 bytes {JMP QWORD [RIP+0x87ce880]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077a717f0 6 bytes {JMP QWORD [RIP+0x86ce840]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077a71840 6 bytes {JMP QWORD [RIP+0x86ee7f0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077a71860 6 bytes {JMP QWORD [RIP+0x880e7d0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort 0000000077a71a50 6 bytes {JMP QWORD [RIP+0x88ce5e0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077a71b60 6 bytes {JMP QWORD [RIP+0x86ae4d0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort 0000000077a71c30 6 bytes {JMP QWORD [RIP+0x876e400]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a71d80 6 bytes {JMP QWORD [RIP+0x886e2b0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077a71d90 6 bytes {JMP QWORD [RIP+0x88ae2a0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077a72100 6 bytes {JMP QWORD [RIP+0x878df30]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 0000000077a72190 6 bytes {JMP QWORD [RIP+0x888dea0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077a72a00 6 bytes {JMP QWORD [RIP+0x87ad630]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077a72a80 6 bytes {JMP QWORD [RIP+0x870d5b0]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077a72b00 6 bytes {JMP QWORD [RIP+0x872d530]}
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Windows\System32\svchost.exe[5756] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077a43ae0 6 bytes {JMP QWORD [RIP+0x85fc550]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077a71400 6 bytes {JMP QWORD [RIP+0x85aec30]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077a715d0 6 bytes {JMP QWORD [RIP+0x874ea60]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077a71640 6 bytes {JMP QWORD [RIP+0x882e9f0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077a71680 6 bytes {JMP QWORD [RIP+0x87ee9b0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077a71720 6 bytes {JMP QWORD [RIP+0x884e910]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077a717b0 6 bytes {JMP QWORD [RIP+0x87ce880]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077a717f0 6 bytes {JMP QWORD [RIP+0x86ce840]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077a71840 6 bytes {JMP QWORD [RIP+0x86ee7f0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077a71860 6 bytes {JMP QWORD [RIP+0x880e7d0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort 0000000077a71a50 6 bytes {JMP QWORD [RIP+0x88ce5e0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077a71b60 6 bytes {JMP QWORD [RIP+0x86ae4d0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort 0000000077a71c30 6 bytes {JMP QWORD [RIP+0x876e400]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a71d80 6 bytes {JMP QWORD [RIP+0x886e2b0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077a71d90 6 bytes {JMP QWORD [RIP+0x88ae2a0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077a72100 6 bytes {JMP QWORD [RIP+0x878df30]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 0000000077a72190 6 bytes {JMP QWORD [RIP+0x888dea0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077a72a00 6 bytes {JMP QWORD [RIP+0x87ad630]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077a72a80 6 bytes {JMP QWORD [RIP+0x870d5b0]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077a72b00 6 bytes {JMP QWORD [RIP+0x872d530]}
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefe149aa5 3 bytes [65, 65, 06]
.text C:\Program Files\Windows Sidebar\sidebar.exe[5376] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters 000007fefe155290 5 bytes [FF, 25, A0, AD, 0A]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtClose 0000000077c1f9c0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4 0000000077c1f9c4 2 bytes [AE, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077c1fc90 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4 0000000077c1fc94 2 bytes [6B, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c1fd44 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c1fd48 2 bytes [56, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection 0000000077c1fda8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4 0000000077c1fdac 2 bytes [5C, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken 0000000077c1fea0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4 0000000077c1fea4 2 bytes [53, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c1ff84 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c1ff88 2 bytes [5F, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077c1ffe4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4 0000000077c1ffe8 2 bytes [77, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077c20064 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4 0000000077c20068 2 bytes [74, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077c20094 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077c20098 2 bytes [59, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort 0000000077c20398 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4 0000000077c2039c 2 bytes [47, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c20530 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4 0000000077c20534 2 bytes [7A, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort 0000000077c20674 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4 0000000077c20678 2 bytes [68, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077c2086c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077c20870 2 bytes [50, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077c20884 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4 0000000077c20888 2 bytes [4A, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077c20dd4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4 0000000077c20dd8 2 bytes [65, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject 0000000077c20eb8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4 0000000077c20ebc 2 bytes [4D, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077c21bc4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4 0000000077c21bc8 2 bytes [62, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem 0000000077c21c94 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4 0000000077c21c98 2 bytes [71, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077c21d6c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4 0000000077c21d70 2 bytes [6E, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077c41217 6 bytes {JMP QWORD [RIP+0x71a7001e]}
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007720103d 6 bytes {JMP QWORD [RIP+0x719b001e]}
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000077201072 6 bytes {JMP QWORD [RIP+0x7198001e]}
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[5164] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW 000000007722c9b5 6 bytes {JMP QWORD [RIP+0x7192001e]}
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtClose 0000000077c1f9c0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4 0000000077c1f9c4 2 bytes [AE, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077c1fc90 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4 0000000077c1fc94 2 bytes [6B, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c1fd44 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c1fd48 2 bytes [56, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection 0000000077c1fda8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4 0000000077c1fdac 2 bytes [5C, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken 0000000077c1fea0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4 0000000077c1fea4 2 bytes [53, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c1ff84 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c1ff88 2 bytes [5F, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077c1ffe4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4 0000000077c1ffe8 2 bytes [77, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077c20064 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4 0000000077c20068 2 bytes [74, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077c20094 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077c20098 2 bytes [59, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort 0000000077c20398 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4 0000000077c2039c 2 bytes [47, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c20530 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4 0000000077c20534 2 bytes [7A, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort 0000000077c20674 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4 0000000077c20678 2 bytes [68, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077c2086c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077c20870 2 bytes [50, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077c20884 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4 0000000077c20888 2 bytes [4A, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077c20dd4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4 0000000077c20dd8 2 bytes [65, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject 0000000077c20eb8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4 0000000077c20ebc 2 bytes [4D, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077c21bc4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4 0000000077c21bc8 2 bytes [62, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem 0000000077c21c94 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4 0000000077c21c98 2 bytes [71, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077c21d6c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4 0000000077c21d70 2 bytes [6E, 71]
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077c41217 6 bytes {JMP QWORD [RIP+0x71a7001e]}
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007720103d 6 bytes {JMP QWORD [RIP+0x719b001e]}
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000077201072 6 bytes {JMP QWORD [RIP+0x7198001e]}
.text C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe[5948] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW 000000007722c9b5 6 bytes {JMP QWORD [RIP+0x7192001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtClose 0000000077c1f9c0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4 0000000077c1f9c4 2 bytes [AE, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077c1fc90 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4 0000000077c1fc94 2 bytes [65, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c1fd44 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c1fd48 2 bytes [50, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection 0000000077c1fda8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4 0000000077c1fdac 2 bytes [56, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken 0000000077c1fea0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4 0000000077c1fea4 2 bytes [4D, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c1ff84 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c1ff88 2 bytes [59, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077c1ffe4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4 0000000077c1ffe8 2 bytes [71, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077c20064 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4 0000000077c20068 2 bytes [6E, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077c20094 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077c20098 2 bytes [53, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort 0000000077c20398 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4 0000000077c2039c 2 bytes [41, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c20530 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4 0000000077c20534 2 bytes [74, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort 0000000077c20674 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4 0000000077c20678 2 bytes [62, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077c2086c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077c20870 2 bytes [4A, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077c20884 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4 0000000077c20888 2 bytes [44, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077c20dd4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4 0000000077c20dd8 2 bytes [5F, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject 0000000077c20eb8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4 0000000077c20ebc 2 bytes [47, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077c21bc4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4 0000000077c21bc8 2 bytes [5C, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem 0000000077c21c94 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4 0000000077c21c98 2 bytes [6B, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077c21d6c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4 0000000077c21d70 2 bytes [68, 71]
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077c41217 6 bytes {JMP QWORD [RIP+0x71a7001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007720103d 6 bytes {JMP QWORD [RIP+0x719b001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000077201072 6 bytes {JMP QWORD [RIP+0x7198001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW 000000007722c9b5 6 bytes {JMP QWORD [RIP+0x7192001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters 000000007580f776 6 bytes {JMP QWORD [RIP+0x719e001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000075812c91 4 bytes {CALL QWORD [RIP+0x71ac000a]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\GDI32.dll!DeleteDC 00000000753658b3 6 bytes {JMP QWORD [RIP+0x7180001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\GDI32.dll!CreateDCA 0000000075367bcc 6 bytes {JMP QWORD [RIP+0x718f001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\GDI32.dll!GetPixel 000000007536cbfb 6 bytes {JMP QWORD [RIP+0x7189001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\GDI32.dll!CreateDCW 000000007536e743 6 bytes {JMP QWORD [RIP+0x718c001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\USER32.dll!SetWinEventHook 000000007586ee09 6 bytes {JMP QWORD [RIP+0x7177001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075877603 6 bytes {JMP QWORD [RIP+0x717a001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 000000007587835c 6 bytes {JMP QWORD [RIP+0x717d001e]}
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[4432] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075bf2538 6 bytes {JMP QWORD [RIP+0x7195001e]}
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtClose 0000000077c1f9c0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4 0000000077c1f9c4 2 bytes [AE, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077c1fc90 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4 0000000077c1fc94 2 bytes [6B, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c1fd44 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c1fd48 2 bytes [56, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection 0000000077c1fda8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4 0000000077c1fdac 2 bytes [5C, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken 0000000077c1fea0 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4 0000000077c1fea4 2 bytes [53, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c1ff84 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c1ff88 2 bytes [5F, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077c1ffe4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4 0000000077c1ffe8 2 bytes [77, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077c20064 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4 0000000077c20068 2 bytes [74, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077c20094 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077c20098 2 bytes [59, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort 0000000077c20398 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4 0000000077c2039c 2 bytes [47, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c20530 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4 0000000077c20534 2 bytes [7A, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort 0000000077c20674 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4 0000000077c20678 2 bytes [68, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077c2086c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077c20870 2 bytes [50, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077c20884 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4 0000000077c20888 2 bytes [4A, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077c20dd4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4 0000000077c20dd8 2 bytes [65, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject 0000000077c20eb8 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4 0000000077c20ebc 2 bytes [4D, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077c21bc4 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4 0000000077c21bc8 2 bytes [62, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem 0000000077c21c94 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4 0000000077c21c98 2 bytes [71, 71]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077c21d6c 3 bytes [FF, 25, 1E]
.text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[6288] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4 0000000077c21d70 2 bytes [6E, 71]