GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-03-31 20:59:07 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-7 SAMSUNG_HD103SJ rev.1AJ10001 931,51GB Running: 3dqski1d.exe; Driver: C:\Users\mati\AppData\Local\Temp\ugldapob.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800037a7000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff800037a7011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f} ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 000000014a2d0460 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 000000014a2d0450 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 000000014a2d0370 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 000000014a2d0470 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 000000014a2d03e0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 000000014a2d0320 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 000000014a2d03b0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 000000014a2d0390 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 000000014a2d02e0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 000000014a2d02d0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 000000014a2d0310 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 000000014a2d03c0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 000000014a2d03f0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 000000014a2d0230 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 000000014a2d0480 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 000000014a2d03a0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 000000014a2d02f0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 000000014a2d0350 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 000000014a2d0290 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 000000014a2d02b0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 000000014a2d03d0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 000000014a2d0330 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 000000014a2d0410 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 000000014a2d0240 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 000000014a2d01e0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 000000014a2d0250 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 000000014a2d0490 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 000000014a2d04a0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 000000014a2d0300 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 000000014a2d0360 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 000000014a2d02a0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 000000014a2d02c0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 000000014a2d0380 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 000000014a2d0340 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 000000014a2d0440 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 000000014a2d0260 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 000000014a2d0270 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 000000014a2d0400 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 000000014a2d01f0 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 000000014a2d0210 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 000000014a2d0200 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 000000014a2d0420 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 000000014a2d0430 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 000000014a2d0220 .text C:\Windows\system32\csrss.exe[416] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 000000014a2d0280 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\wininit.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\wininit.exe[488] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 000000014a2d0460 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 000000014a2d0450 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 000000014a2d0370 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 000000014a2d0470 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 000000014a2d03e0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 000000014a2d0320 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 000000014a2d03b0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 000000014a2d0390 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 000000014a2d02e0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 000000014a2d02d0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 000000014a2d0310 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 000000014a2d03c0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 000000014a2d03f0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 000000014a2d0230 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 000000014a2d0480 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 000000014a2d03a0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 000000014a2d02f0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 000000014a2d0350 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 000000014a2d0290 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 000000014a2d02b0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 000000014a2d03d0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 000000014a2d0330 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 000000014a2d0410 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 000000014a2d0240 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 000000014a2d01e0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 000000014a2d0250 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 000000014a2d0490 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 000000014a2d04a0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 000000014a2d0300 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 000000014a2d0360 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 000000014a2d02a0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 000000014a2d02c0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 000000014a2d0380 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 000000014a2d0340 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 000000014a2d0440 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 000000014a2d0260 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 000000014a2d0270 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 000000014a2d0400 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 000000014a2d01f0 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 000000014a2d0210 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 000000014a2d0200 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 000000014a2d0420 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 000000014a2d0430 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 000000014a2d0220 .text C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 000000014a2d0280 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\services.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\services.exe[544] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\lsass.exe[564] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\lsm.exe[572] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\winlogon.exe[696] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[708] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\svchost.exe[708] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[820] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\atiesrxx.exe[884] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\System32\svchost.exe[944] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\System32\svchost.exe[944] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\System32\svchost.exe[992] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\System32\svchost.exe[992] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[116] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\svchost.exe[116] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[380] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\svchost.exe[380] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\svchost.exe[1156] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\atieclxx.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\Dwm.exe[1576] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000100070460 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000100070450 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000100070370 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000100070470 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 00000001000703e0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000100070320 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 00000001000703b0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000100070390 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 00000001000702d0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000100070310 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 00000001000703c0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000100070230 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000100070480 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000100070350 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000100070290 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000100070330 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000100070410 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000100070240 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000100070250 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000100070490 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000100070300 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000100070360 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 00000001000702a0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 00000001000702c0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000100070380 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000100070340 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000100070440 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000100070260 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000100070270 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000100070400 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000100070210 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000100070200 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000100070420 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000100070430 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\Explorer.EXE[1600] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000100070280 .text C:\Windows\Explorer.EXE[1600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000100070460 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000100070450 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000100070370 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000100070470 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 00000001000703e0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000100070320 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 00000001000703b0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000100070390 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 00000001000702d0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000100070310 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 00000001000703c0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000100070230 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000100070480 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000100070350 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000100070290 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000100070330 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000100070410 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000100070240 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000100070250 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000100070490 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000100070300 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000100070360 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 00000001000702a0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 00000001000702c0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000100070380 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000100070340 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000100070440 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000100070260 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000100070270 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000100070400 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000100070210 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000100070200 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000100070420 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000100070430 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000100070280 .text C:\Windows\System32\spoolsv.exe[1628] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\svchost.exe[1672] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\taskhost.exe[1680] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1780] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076dc8769 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1780] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ec1465 2 bytes [EC, 76] .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ec14bb 2 bytes [EC, 76] .text ... * 2 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\taskeng.exe[1812] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2016] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[2084] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2128] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Users\mati\AppData\Roaming\uTorrent\uTorrent.exe[2244] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Users\mati\AppData\Roaming\uTorrent\uTorrent.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ec1465 2 bytes [EC, 76] .text C:\Users\mati\AppData\Roaming\uTorrent\uTorrent.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ec14bb 2 bytes [EC, 76] .text ... * 2 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text c:\Program Files\Bonjour\mDNSResponder.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[2804] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000074371a22 2 bytes [37, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000074371ad0 2 bytes [37, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000074371b08 2 bytes [37, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000074371bba 2 bytes [37, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000074371bda 2 bytes [37, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ec1465 2 bytes [EC, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ec14bb 2 bytes [EC, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2956] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files (x86)\Prime95\prime95.exe[3008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[3028] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\System32\svchost.exe[1952] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1484] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe[2340] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2640] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076dc8769 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2640] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[1900] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[1900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ec1465 2 bytes [EC, 76] .text C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe[1900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ec14bb 2 bytes [EC, 76] .text ... * 2 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\SearchIndexer.exe[3436] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000100070460 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000100070450 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000100070370 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000100070470 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 00000001000703e0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000100070320 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 00000001000703b0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000100070390 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 00000001000702e0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 00000001000702d0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000100070310 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 00000001000703c0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 00000001000703f0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000100070230 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000100070480 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 00000001000703a0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 00000001000702f0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000100070350 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000100070290 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 00000001000702b0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 00000001000703d0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000100070330 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000100070410 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000100070240 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 00000001000701e0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000100070250 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000100070490 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 00000001000704a0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000100070300 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000100070360 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 00000001000702a0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 00000001000702c0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000100070380 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000100070340 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000100070440 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000100070260 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000100070270 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000100070400 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 00000001000701f0 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000100070210 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000100070200 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000100070420 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000100070430 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000100070220 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000100070280 .text C:\Program Files\iPod\bin\iPodService.exe[3468] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\svchost.exe[4288] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000100070460 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000100070450 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000100070370 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000100070470 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 00000001000703e0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000100070320 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 00000001000703b0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000100070390 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 00000001000702e0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 00000001000702d0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000100070310 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 00000001000703c0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 00000001000703f0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000100070230 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000100070480 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 00000001000703a0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 00000001000702f0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000100070350 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000100070290 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 00000001000702b0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 00000001000703d0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000100070330 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000100070410 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000100070240 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 00000001000701e0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000100070250 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000100070490 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 00000001000704a0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000100070300 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000100070360 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 00000001000702a0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 00000001000702c0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000100070380 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000100070340 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000100070440 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000100070260 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000100070270 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000100070400 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 00000001000701f0 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000100070210 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000100070200 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000100070420 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000100070430 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000100070220 .text C:\Windows\System32\svchost.exe[4508] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000100070280 .text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[2280] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] .text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[2280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ec1465 2 bytes [EC, 76] .text C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe[2280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ec14bb 2 bytes [EC, 76] .text ... * 2 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077ca1360 5 bytes JMP 0000000077e00460 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077ca13b0 5 bytes JMP 0000000077e00450 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077ca1510 5 bytes JMP 0000000077e00370 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077ca1560 5 bytes JMP 0000000077e00470 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077ca1570 5 bytes JMP 0000000077e003e0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077ca1620 5 bytes JMP 0000000077e00320 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 5 bytes JMP 0000000077e003b0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077ca1670 5 bytes JMP 0000000077e00390 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077ca16b0 5 bytes JMP 0000000077e002e0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077ca1730 5 bytes JMP 0000000077e002d0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077ca1750 5 bytes JMP 0000000077e00310 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077ca1790 5 bytes JMP 0000000077e003c0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077ca17e0 5 bytes JMP 0000000077e003f0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077ca1940 5 bytes JMP 0000000077e00230 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077ca1b00 5 bytes JMP 0000000077e00480 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077ca1b30 5 bytes JMP 0000000077e003a0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077ca1c10 5 bytes JMP 0000000077e002f0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077ca1c20 5 bytes JMP 0000000077e00350 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077ca1c80 5 bytes JMP 0000000077e00290 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077ca1d10 5 bytes JMP 0000000077e002b0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 5 bytes JMP 0000000077e003d0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077ca1d40 5 bytes JMP 0000000077e00330 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077ca1db0 5 bytes JMP 0000000077e00410 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077ca1de0 5 bytes JMP 0000000077e00240 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077ca20a0 5 bytes JMP 0000000077e001e0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077ca2160 5 bytes JMP 0000000077e00250 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077ca2190 5 bytes JMP 0000000077e00490 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077ca21a0 5 bytes JMP 0000000077e004a0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077ca21d0 5 bytes JMP 0000000077e00300 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077ca21e0 5 bytes JMP 0000000077e00360 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077ca2240 5 bytes JMP 0000000077e002a0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077ca2290 5 bytes JMP 0000000077e002c0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077ca22c0 5 bytes JMP 0000000077e00380 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077ca22d0 5 bytes JMP 0000000077e00340 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077ca25c0 5 bytes JMP 0000000077e00440 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077ca27c0 5 bytes JMP 0000000077e00260 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077ca27d0 5 bytes JMP 0000000077e00270 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 5 bytes JMP 0000000077e00400 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077ca29a0 5 bytes JMP 0000000077e001f0 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077ca29b0 5 bytes JMP 0000000077e00210 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077ca2a20 5 bytes JMP 0000000077e00200 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077ca2a80 5 bytes JMP 0000000077e00420 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077ca2a90 5 bytes JMP 0000000077e00430 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077ca2aa0 5 bytes JMP 0000000077e00220 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077ca2b80 5 bytes JMP 0000000077e00280 .text C:\Windows\system32\AUDIODG.EXE[2896] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a8eecd 1 byte [62] .text C:\Users\mati\Desktop\Nowy folder\3dqski1d.exe[6104] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076dea2ba 1 byte [62] ---- Processes - GMER 2.1 ---- Library C:\Users\mati\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1600] (GG drive menu/GG Network S.A.)(2013- 000000005ff80000 ---- Files - GMER 2.1 ---- File C:\avast! sandbox 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86) 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86)\Google 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86)\Google\Chrome 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86)\Google\Chrome\Application 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86)\Google\Chrome\Application\32.0.1700.76 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Program Files (x86)\Google\Chrome\Application\debug.log 1089 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications\Windows 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk 8192 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log 1048576 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS000E0.log 1048576 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log 1048576 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal 4640 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt 4 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001bc 17685 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 303104 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 5775360 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 22028288 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 33562624 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000006 155692 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000a 29887 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000b 123375 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000c 59173 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000d 23043 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000e 42962 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000f 115197 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000010 44297 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000011 17224 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000012 32775 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000013 33471 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000014 42794 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000015 282861 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000016 16851 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000018 54594 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000019 84194 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001a 132238 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001b 147874 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001c 21926 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001d 38366 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001e 63921 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00001f 66139 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000020 55853 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000021 271699 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000022 99315 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000023 586662 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000024 139129 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000025 140007 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000026 36148 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000027 18534 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000028 451252 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000029 57335 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002a 316585 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002c 26273 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002d 456127 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002e 73316 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002f 231550 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000031 202029 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000032 200648 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000033 187463 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000034 757062 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000035 196700 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000036 663132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000037 218479 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000038 210404 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000039 204927 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003a 204274 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003b 36161 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003c 215297 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003d 202879 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003e 49374 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000040 40784 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000041 31652 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000042 49487 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000043 44658 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000044 23577 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000045 22986 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000046 90290 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000047 46592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000048 626056 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000049 33882 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004a 18608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004b 33140 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004c 27786 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004d 282861 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004e 77160 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004f 100298 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000050 94308 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000051 29515 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000052 162384 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000054 141370 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000055 467378 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000056 1004698 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000057 643364 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000058 65874 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000059 50418 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005a 581209 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005b 28624 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005c 242975 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005d 354409 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005e 38309 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00005f 27576 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000060 51768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000061 20302 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000062 1138233 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000063 21417 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000064 32485 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000065 306131 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000074 19746 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000078 179413 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000079 21692 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007a 42146 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007b 54722 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007c 852926 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007d 42130 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007e 34155 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00007f 24664 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000080 214498 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000081 19373 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000083 17091 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000088 300238 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000089 27723 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008a 27566 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008b 171490 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008c 17078 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008d 62874 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008e 840639 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00008f 31549 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000017 51963 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00002b 46098 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00003f 205380 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000053 148882 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000075 188574 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000090 335331 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a5 33935 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000bf 17533 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d3 224348 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e9 65695 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ff 22157 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000113 62526 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000133 37572 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000148 20314 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000160 19729 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000174 22673 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a3 25447 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000091 1673643 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000092 130396 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000093 62845 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000094 39185 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000095 16724 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000096 130471 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000097 417785 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000099 241926 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009a 25540 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009b 85014 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009c 17877 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009d 215357 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009e 57813 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00009f 215460 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a0 128628 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a1 179116 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a2 16830 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a3 20399 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a4 113514 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a6 96797 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a7 68425 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a8 116796 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000a9 17058 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000aa 244115 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ab 80223 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ac 17132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ad 89178 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ae 108581 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000af 83757 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b0 92685 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b1 108692 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b2 181453 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b3 83374 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b4 128098 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b5 88996 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b6 16485 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b7 17876 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000b8 44801 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c0 18825 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c1 41976 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c2 66158 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c3 41997 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c4 29548 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c5 85792 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c6 25025 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c7 134525 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c8 23192 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000c9 193444 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ca 158915 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000cb 160810 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000cc 298653 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000cd 357578 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ce 214872 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000cf 202223 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d0 188240 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d1 184820 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d2 304528 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d4 176957 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d5 193181 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d6 278673 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d7 179903 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d8 268317 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000d9 249754 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000da 212540 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000db 231489 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000de 140284 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000df 99145 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e0 19998 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e1 20510 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e2 26999 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e3 32819 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e4 16716 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e5 43858 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e6 49879 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000e7 123638 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ea 100851 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000eb 19998 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ec 34572 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ed 45292 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000ee 35902 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f1 63580 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f2 45703 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f3 33620 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f4 17359 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f5 70446 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f6 16459 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f7 34226 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f8 29186 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000f9 20789 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000fa 29038 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000fc 46255 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000fd 28960 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0000fe 64843 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000100 68300 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000101 34164 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000102 26183 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000103 23879 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000104 26257 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000105 18336 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000106 40709 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000107 24605 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000108 22995 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000109 68342 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010a 139285 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010b 52225 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010c 83938 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010d 30848 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010e 168883 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00010f 291499 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000110 28085 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000111 52225 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00011e 33933 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00011f 54823 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000120 28327 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000121 42316 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000123 24749 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000125 17620 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000126 24944 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000127 24596 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000128 28776 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000129 18188 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012a 17360 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012b 30861 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012c 32980 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012d 29571 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012e 19691 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00012f 37356 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000130 80374 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000131 26084 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000132 27871 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000134 229662 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000135 35000 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000136 41093 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000137 93938 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000138 26956 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000139 29128 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00013b 53346 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00013c 28988 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00013e 16716 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00013f 16387 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000140 35292 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000141 93658 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000142 20108 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000143 38412 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000144 37676 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000145 20732 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000146 29325 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000147 25154 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000149 49482 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00014a 62405 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00014e 16884 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00014f 38888 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000150 81406 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000151 105022 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000152 19919 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000153 35984 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000154 17887 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000155 17644 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000159 16484 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015a 23889 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015b 16450 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015c 19750 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015d 20649 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015e 17088 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00015f 16741 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000161 58812 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000162 19438 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000163 19939 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000164 68234 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000165 22038 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000166 18037 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000167 24389 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000168 19197 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000169 16521 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016a 21494 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016b 16999 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016c 17038 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016d 18767 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016e 19025 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00016f 16449 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000170 17882 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000171 16420 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000172 19164 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000173 26429 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000175 24438 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000176 17210 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000177 19428 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000178 63685 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000179 18021 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00017a 17038 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00017b 32988 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00017d 42565 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00017e 26911 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000182 26442 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000188 27132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00018c 21936 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00018e 78921 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000194 44995 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000195 87889 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000198 103588 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a1 16748 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a2 19610 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a6 38804 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a7 40232 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001a8 39924 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ab 30833 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ad 35678 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ae 90290 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001af 32821 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b0 20765 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b1 18096 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b2 19721 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b3 17264 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b4 36439 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b5 146065 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b6 28472 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b7 21184 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b8 21720 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001b9 17296 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ba 57768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001bb 19101 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001bd 410708 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001be 26164 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001bf 23971 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c0 50161 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c1 19676 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c2 26037 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c3 17481 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c4 25042 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c5 18678 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c6 58721 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c7 30781 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c8 37923 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001c9 39931 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ca 19721 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001cb 21101 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001cc 17391 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001cd 21332 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001ce 88017 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001cf 20906 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d1 18300 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d2 20856 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d3 20755 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d4 20822 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d5 17629 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d6 24379 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d7 22423 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d8 23620 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d9 17750 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001da 23946 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0002bc 17951 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003f8 19353 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000402 16753 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000406 23474 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000420 19758 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00042b 19595 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00042f 23647 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000507 26023 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000509 25676 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000510 16658 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000545 69952 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000546 21408 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000547 24433 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000549 22103 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00054a 22405 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00054b 20533 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00054d 159484 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00054f 34579 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000550 80823 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000551 52302 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000552 22039 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000553 21846 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000554 18165 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000555 24605 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000556 67637 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000557 19889 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000558 32546 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000559 212299 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00055b 132548 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00055c 117976 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00055e 16661 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00055f 17960 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000560 25987 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000561 64819 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000562 56508 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000563 33789 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000565 22644 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c9 50358 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ca 69244 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005cb 18414 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005cc 27843 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005cd 30822 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ce 32905 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005cf 40372 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d0 28284 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d2 55010 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d4 42368 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d6 55788 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d7 46862 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d8 139068 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005da 32038 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005db 54484 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005dd 34763 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005de 27614 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005df 28434 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e0 44483 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e1 30195 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e2 70928 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e3 33186 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e4 18960 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e5 30936 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e6 64879 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e7 43571 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e8 34032 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005e9 40577 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005eb 121840 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ed 16772 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ee 19278 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ef 199851 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f0 25920 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f1 40412 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f2 52419 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f3 54814 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f4 18493 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f5 169947 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f6 31269 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f7 50939 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f8 18583 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005f9 39307 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005fa 17825 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005fb 18615 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005fc 25250 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005fd 17362 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ff 20711 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000600 16511 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000601 23137 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000602 28927 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000603 72174 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000604 20822 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000605 22885 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000606 54594 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000607 205136 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000608 23297 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000609 19760 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060a 47957 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060b 22622 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060c 40199 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060d 25404 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060e 27531 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00060f 26561 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000610 80462 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000611 50114 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000613 27948 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000614 92629 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000615 17274 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000616 34084 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000617 40507 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000618 56553 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000619 39866 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061a 42943 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061b 19583 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061c 51301 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061d 63427 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061e 51362 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00061f 51090 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000620 21387 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000621 41955 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000622 47811 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000623 40913 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000624 34314 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000625 36789 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000627 45112 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000628 49946 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000629 30947 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062a 62564 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062b 22385 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062c 27881 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062d 27344 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062e 30931 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00062f 37605 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000630 51050 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000631 38772 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000632 47404 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000633 40507 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000634 28365 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000635 26720 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000636 33096 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000637 28027 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000638 37650 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000639 37936 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063b 19404 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063c 22680 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063d 180614 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063e 57768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063f 29372 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000640 18378 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000641 19111 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000642 113166 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000643 56284 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000644 78306 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000645 43030 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000646 84621 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000647 34984 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000648 46415 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000649 16397 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064a 30849 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064b 25517 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064c 55569 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064d 25517 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064f 53787 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000650 18242 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000651 111566 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000652 24215 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000653 37770 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000654 20595 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000655 27663 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000656 38032 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000657 19137 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000658 57769 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000659 17490 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065a 18401 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065b 17796 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065c 20258 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065d 17851 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065e 20389 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065f 21982 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000660 20759 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000661 17328 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000663 27147 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000664 27147 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000665 16990 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000666 66112 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000667 66735 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000668 169640 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000669 169640 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066a 52545 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066b 152551 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066c 150008 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066d 68278 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066e 94932 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066f 71112 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000670 34819 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000671 78083 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000672 199227 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000673 215628 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000674 35206 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000675 218868 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000677 87527 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000678 90161 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000679 28607 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067a 81744 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067b 69023 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067c 33007 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067d 91747 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067e 123235 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000680 36991 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000681 25170 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000682 24076 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000683 20044 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000684 92439 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000685 68615 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000686 49427 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000687 69378 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000688 63970 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000689 29556 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068a 20159 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068c 52494 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068d 81716 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068e 101780 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068f 47711 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000691 65351 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000692 154201 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000693 123798 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000694 136718 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000695 25512 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000697 70567 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000698 51341 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000699 49357 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069a 34027 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069c 19730 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069d 17324 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069e 33335 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069f 56113 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a0 18383 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a2 86859 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a3 70024 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a7 63144 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a8 34696 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a9 294880 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006aa 29548 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ab 16780 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ac 43888 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ad 16584 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ae 16914 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006af 16385 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b0 17820 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b1 19164 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b2 17996 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b3 19783 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b4 177802 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b5 53408 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b7 17936 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b8 19166 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b9 16840 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ba 18053 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bb 20747 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bc 18161 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bd 19213 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006be 16902 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bf 16471 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c0 17491 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c1 16633 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c2 16608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c3 17748 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c4 17015 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c5 18937 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c6 17374 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c7 18650 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c8 17085 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c9 17027 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cb 18168 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cc 18500 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cd 17769 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ce 24611 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cf 16649 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d0 16501 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d1 17534 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d2 18595 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d3 17590 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d4 19616 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d5 19130 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d6 18486 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d7 17108 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d8 18492 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d9 19339 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006da 18036 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006db 18047 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006dc 16690 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006dd 16447 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006df 17172 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e0 17420 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e1 16787 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e2 19112 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e3 16386 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e4 16463 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e5 21304 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e6 18596 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e7 18281 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e8 17806 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e9 18020 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ea 17576 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006eb 16788 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ec 17934 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ed 18387 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ee 19480 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ef 18768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f0 21222 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f1 18652 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f3 17978 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f4 18522 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f5 16889 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f6 17763 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f7 17620 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f8 16706 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f9 16385 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fa 16534 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fb 21546 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fc 16994 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000700 120562 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000701 43603 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000704 64120 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000705 33221 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000706 19744 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000707 24049 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000708 37990 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0001d0 18375 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00050b 24298 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00055a 22883 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005d5 23422 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ea 70928 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005fe 20140 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000612 47789 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000626 25798 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00063a 19660 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00064e 33836 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000662 32792 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000676 91072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068b 195686 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a1 29345 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b6 20553 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ca 16918 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006de 18915 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f2 17530 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000709 23025 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071d 29696 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000732 47678 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000746 118271 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075a 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076e 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000782 71290 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000796 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007aa 28691 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007be 20067 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d2 26306 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e6 94672 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007fa 39221 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080e 17174 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070a 36116 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070b 60771 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070c 18559 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070d 124456 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070e 19647 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070f 58182 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000710 64497 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000711 45226 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000712 38012 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000713 20952 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000714 17561 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000715 25839 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000716 16877 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000717 16956 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000718 20129 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000719 17538 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071a 23535 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071b 21132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071c 20636 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071e 22444 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071f 30543 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000720 26343 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000721 18312 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000724 19744 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000725 37990 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000726 55852 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000727 75604 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000728 80162 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000729 25839 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072a 38359 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072b 36157 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072c 57768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072e 31365 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072f 71322 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000730 19827 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000731 43581 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000733 23712 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000734 40173 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000735 27163 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000736 33776 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000737 17413 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000738 23262 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000739 21921 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073a 60453 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073b 89018 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073c 17017 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073d 21611 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073e 34764 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00073f 19999 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000740 20614 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000741 18113 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000742 29715 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000743 23494 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000744 17322 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000745 22929 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000747 135625 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000748 20680 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000749 35467 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074a 36280 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074b 397815 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074c 21083 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074d 16573 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074e 38169 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00074f 30537 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000750 28825 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000751 233967 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000752 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000753 528730 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000754 33013 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000755 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000756 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000757 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000758 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000759 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075b 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075c 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075d 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075e 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00075f 79204 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000760 75972 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000761 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000762 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000763 26741 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000764 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000765 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000766 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000767 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000768 18717 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000769 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076a 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076b 49430 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076c 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076d 40025 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00076f 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000770 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000771 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000772 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000773 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000774 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000775 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000776 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000777 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000778 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000779 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077a 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077b 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077c 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077d 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077e 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00077f 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000780 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000781 30547 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000783 20642 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000784 19282 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000785 16683 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000786 25104 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000787 23436 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000788 22400 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000789 19473 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078a 16772 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078b 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078c 27740 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078d 47207 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078e 1130496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00078f 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000790 656700 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000791 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000792 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000793 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000794 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000795 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000797 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000798 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000799 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079a 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079b 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079c 93194 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079d 99817 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079e 65574 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00079f 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a0 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a1 19400 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a2 237568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a3 25168 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a4 1134592 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a5 43525 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a6 47604 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a7 39091 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a8 84386 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007a9 62899 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ab 63111 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ac 65842 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ad 23743 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ae 23941 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007af 249856 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b0 561152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b1 249856 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b2 561152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b3 249856 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b4 26727 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b5 249856 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b6 561152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b7 27569 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b8 561152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007b9 104719 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ba 65568 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007bb 73703 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007bc 16422 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007bd 18127 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007bf 16827 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c0 85152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c1 98659 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c2 58287 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c3 42643 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c4 23630 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c5 103936 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c6 97408 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c7 57478 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c8 144196 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007c9 53947 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ca 53947 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007cb 55752 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007cc 84448 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007cd 123713 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ce 132092 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007cf 39497 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d0 64278 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d1 26064 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d3 35428 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d4 163250 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d5 35691 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d6 19585 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d7 23779 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d8 31945 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007d9 28284 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007da 61335 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007db 68515 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007dc 52563 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007dd 51572 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007de 43041 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007df 42791 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e0 45706 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e1 63149 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e2 66346 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e3 79389 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e4 43003 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e5 22335 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e7 16753 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e8 207811 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007e9 37456 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ea 18272 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007eb 22189 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ec 26078 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ed 33535 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ee 30143 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ef 27368 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f0 60881 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f1 46534 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f2 23447 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f3 20470 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f4 17217 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f5 72479 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f6 23620 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f7 38484 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f8 44702 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007f9 28995 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007fb 82537 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007fc 56273 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007fd 88113 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007fe 22131 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0007ff 17302 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000800 24098 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000802 63750 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000803 32445 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000804 20645 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000805 37922 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000806 42690 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000807 18718 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000808 35979 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000809 46700 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080a 33972 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080b 55768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080c 56303 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080d 16608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00080f 22667 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000810 33186 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000811 20854 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000812 56803 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000813 48132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000814 32380 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000815 36187 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000816 371159 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000817 55787 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000818 22605 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000819 38106 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081a 26033 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081b 116104 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081c 54490 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081d 38377 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081e 36751 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00081f 18420 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000820 81765 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000821 40578 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000822 62303 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000823 23506 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000824 31581 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000825 68700 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000826 57768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000827 234754 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Cache\index 524656 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\databases 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db 7168 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db-journal 5672 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\databases\http_tnttorrent.info_0 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\databases\http_tnttorrent.info_0\1 7168 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies 6144 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000222.log 542 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\CURRENT 16 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOCK 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG 148 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old 148 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\MANIFEST-000221 902 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\000316.ldb 7189 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\000317.log 114 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT 16 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG 270 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old 271 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000315 466 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Extensions 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0 8192 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 270336 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_2 8192 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_3 8192 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index 262512 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache 1183187 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_farmerama.bigpoint.com_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gomekmidlodglbbmalcneegieacbdmki_0.localstorage 605184 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gomekmidlodglbbmalcneegieacbdmki_0.localstorage-journal 16384 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pdnkcidphdcakpkheohlhocaicfamjie_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage 5120 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage-journal 5672 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.pl_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_farmerama.bigpoint.com_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tnttorrent.info_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tnttorrent.info_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.farmerama.pl_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.farmerama.pl_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.youtube.com_0.localstorage 3072 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.youtube.com_0.localstorage-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Login Data 18432 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_0 45056 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_1 270336 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_2 1056768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_3 4202496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Media Cache\index 524656 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor 239616 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs 27648 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal 3608 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\bbcdn-bbnaut.ibillboard.com 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\bbcdn-bbnaut.ibillboard.com\server-static-files 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\bbcdn-bbnaut.ibillboard.com\server-static-files\bbnaut.swf 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\bbcdn-bbnaut.ibillboard.com\server-static-files\bbnaut.swf\evercookie.sol 75 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net\swf 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net\swf\mlf.swf 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net\swf\mlf.swf\farm# 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net\swf\mlf.swf\farm#\erama_alertpoplist_21266220.sol 67655 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\farmerama-171.level3.bpcdn.net\swf\mlf.swf\mlf.sol 46 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support\flashplayer 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support\flashplayer\sys 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support\flashplayer\sys\#bbcdn-bbnaut.ibillboard.com 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support\flashplayer\sys\#bbcdn-bbnaut.ibillboard.com\settings.sol 97 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\macromedia.com\support\flashplayer\sys\settings.sol 822 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\V7L7VV3E\s.ytimg.com 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Preferences 171565 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\QuotaManager 13312 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal 8768 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000359.log 3957725 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000361.ldb 1566544 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT 16 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG 1234 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old 271 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000355 462 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Shortcuts 73728 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal 16384 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Top Sites 299008 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal 16384 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity 964 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Web Data 77824 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal 12848 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Local State 56105 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom 7422648 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom Prefix Set 1357734 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies 6144 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Csd Whitelist 135496 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Download 1117900 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Download Whitelist 19504 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing Extension Blacklist 6940 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\Safe Browsing IP Blacklist 48 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libEGL.dll 112128 bytes executable File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libGLESv2.dll 4591616 bytes executable File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\manifest.fingerprint 9 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\manifest.json 202 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Microsoft 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Microsoft\Windows 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat 128 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\Cache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\Cache\_CACHE_MAP_ 276 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-malware-shavar.cache 12 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-malware-shavar.pset 536028 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-malware-shavar.sbstore 1250714 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-phish-shavar.cache 12 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-phish-shavar.pset 851796 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\goog-phish-shavar.sbstore 630607 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-malware-simple.cache 44 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-malware-simple.pset 16 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-malware-simple.sbstore 232 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-phish-simple.cache 44 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-phish-simple.pset 16 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\safebrowsing\test-phish-simple.sbstore 232 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\startupCache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\startupCache\startupCache.4.little 29224 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\_CACHE_CLEAN_ 1 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Temp 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Local\Temp\acro_rd_dir 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\098A74825DEB4C50FAE88C91A0B9713D_A2E842D12728FEFF33CBD32D0983455D 1514 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1F15462BC5A6655F7F25415F98A0571C_D06DFA05666A128B343810BD6BD481F3 1547 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D 1582 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384 1895 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7 1987 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\098A74825DEB4C50FAE88C91A0B9713D_A2E842D12728FEFF33CBD32D0983455D 418 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1F15462BC5A6655F7F25415F98A0571C_D06DFA05666A128B343810BD6BD481F3 380 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D 292 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384 422 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7 426 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Crypto 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Crypto\RSA 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3372699847-3746653199-2843972665-1000 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3372699847-3746653199-2843972665-1000\0b6ffc9610232ee9ff567a4d9dc324d3_889b593d-06f7-4801-b468-18baa8f507a0 1489 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Windows 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Windows\Cookies 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Microsoft\Windows\Cookies\container.dat 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\addons.json 24 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\blocklist.xml 108261 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\cert8.db 147456 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\content-prefs.sqlite 229376 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\formhistory.sqlite 688128 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\healthreport.sqlite 1146880 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\key3.db 16384 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\localstore.rdf 6060 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\marionette.log 57 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\mimeTypes.rdf 9422 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\parent.lock 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\permissions.sqlite 65536 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\prefs.js 8084 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\signons.sqlite 393216 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\urlclassifierkey3.txt 154 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\webapps 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\webapps\webapps.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\webappsstore.sqlite 1802240 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcMultiRatingStorage.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcPhishingStorage.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcRatingStorage.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcUserStorage.json 152 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcVotingStorage.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\Mozilla\Firefox\Profiles\05e35acy.default-1386688911807\wrcWarningStorage.json 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\dht_feed.dat 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\dht_feed.dat.old 2 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\race_07_with_5_addon_pack.torrent 20675 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\resume.dat 95947 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\resume.dat.old 96001 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\settings.dat 278076 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\settings.dat.old 278076 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\share 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\AppData\Roaming\uTorrent\updates.dat 295 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\GoogleEarthPluginSetup.exe 819160 bytes executable File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\bin 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\bin\data-g.bin 5067977 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\Redist 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\Redist\dxwebsetup.exe 299864 bytes executable File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\Redist\vcredist_x86.exe 4216840 bytes executable File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\race_07_with_5_addon_pack\setup.exe 2043669 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\XRG_drift_Drift1967.set 132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Users\mati\Downloads\XRT_drift_Nyze1945.set 132 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf 22114 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch\CHROME.EXE-D999B1BA.pf 164196 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch\FIREFOX.EXE-18ACFCFF.pf 167376 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch\FLASHPLAYERPLUGIN_11_9_900_17-B4E172B4.pf 55804 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Prefetch\PLUGIN-CONTAINER.EXE-F1B02F03.pf 63734 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Rescache 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Rescache\rc0023 0 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\C\Windows\Rescache\rc0023\rescache.hit 8296 bytes File C:\avast! sandbox\S-1-5-21-3372699847-3746653199-2843972665-1000\webStorage\snx_fs.dat 264892 bytes File C:\avast! sandbox\snx_rhive 262144 bytes File C:\avast! sandbox\snx_rhive.LOG1 41984 bytes File C:\avast! sandbox\snx_rhive.LOG2 0 bytes File C:\avast! sandbox\snx_rhive{12bb4139-82a4-11e3-b2b6-485b39cfb238}.TM.blf 65536 bytes File C:\avast! sandbox\snx_rhive{12bb4139-82a4-11e3-b2b6-485b39cfb238}.TMContainer00000000000000000001.regtrans-ms 524288 bytes File C:\avast! sandbox\snx_rhive{12bb4139-82a4-11e3-b2b6-485b39cfb238}.TMContainer00000000000000000002.regtrans-ms 524288 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BC12.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BC42.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BCE0.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BD5F.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDA0.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDD0.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BDF2.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BE13.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BE34.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BE55.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BE76.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BE98.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEB9.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEDA.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BEFB.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BF1C.tmp 0 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BF1D.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BF3F.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BF60.tmp 0 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BF61.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFA1.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFC2.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\BFF3.tmp 28134 bytes File C:\Users\mati\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\C043.tmp 28134 bytes ---- EOF - GMER 2.1 ----