GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2012-12-07 17:05:33
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 SAMSUNG_HD502HI rev.1AG01118
Running: gmer.exe; Driver: C:\DOCUME~1\Darek\USTAWI~1\Temp\fwxyykow.sys


---- System - GMER 1.0.15 ----

SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwClose [0xB4D2BC56]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwCreateKey [0xB4D2BB12]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwDeleteKey [0xB4D2C0C6]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwDeleteValueKey [0xB4D2BFF0]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwDuplicateObject [0xB4D2B6E8]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwOpenKey [0xB4D2BBEC]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwOpenProcess [0xB4D2B628]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwOpenThread [0xB4D2B68C]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwQueryValueKey [0xB4D2BD0C]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwRenameKey [0xB4D2C194]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwRestoreKey [0xB4D2BCCC]
SSDT                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwSetValueKey [0xB4D2BE4C]

INT 0x63                                                                  ?                                                                                                                                                     8A88FCC8
INT 0x63                                                                  ?                                                                                                                                                     8A88FCC8
INT 0x63                                                                  ?                                                                                                                                                     8A738CC8
INT 0x63                                                                  ?                                                                                                                                                     8A88FCC8
INT 0x83                                                                  ?                                                                                                                                                     8A738CC8
INT 0xA4                                                                  ?                                                                                                                                                     8A738CC8
INT 0xB4                                                                  ?                                                                                                                                                     8A738CC8

Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwCreateProcessEx [0xB4D384FE]
Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwCreateSection [0xB4D38322]
Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ZwLoadDriver [0xB4D3845C]
Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 NtCreateSection
Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ObInsertObject
Code                                                                      \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                                                                 ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text                                                                     ntkrnlpa.exe!ZwCallbackReturn + 2CD4                                                                                                                  80504560 4 Bytes  [E8, B6, D2, B4]
PAGE                                                                      ntkrnlpa.exe!ZwLoadDriver                                                                                                                             8058413A 7 Bytes  JMP B4D38460 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE                                                                      ntkrnlpa.exe!NtCreateSection                                                                                                                          805AB3AE 7 Bytes  JMP B4D38326 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE                                                                      ntkrnlpa.exe!ObMakeTemporaryObject                                                                                                                    805BC512 5 Bytes  JMP B4D344BA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE                                                                      ntkrnlpa.exe!ObInsertObject                                                                                                                           805C2F96 5 Bytes  JMP B4D35972 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE                                                                      ntkrnlpa.exe!ZwCreateProcessEx                                                                                                                        805D1136 7 Bytes  JMP B4D38502 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.sptd1                                                                    C:\WINDOWS\system32\drivers\sptd.sys                                                                                                                  entry point in ".sptd1" section [0xB7F8D346]
.sfrelocÿÿÿÿsfsync04unknown last section [0xB7E4F000, 0xBC8, 0x40000040]  C:\WINDOWS\system32\drivers\sfsync04.sys                                                                                                              unknown last section [0xB7E4F000, 0xBC8, 0x40000040]
.text                                                                     C:\WINDOWS\system32\DRIVERS\nv4_mini.sys                                                                                                              section is writeable [0xB74D9360, 0x3D46A5, 0xE8000020]
.text                                                                     USBPORT.SYS!DllUnload                                                                                                                                 B74918AC 5 Bytes  JMP 8A7381D8 
init                                                                      C:\WINDOWS\system32\drivers\monfilt.sys                                                                                                               entry point in "init" section [0xB4FED280]

---- User code sections - GMER 1.0.15 ----

.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] kernel32.dll!CreateProcessW                                                                                 7C802336 5 Bytes  JMP 00B15001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] kernel32.dll!GetQueuedCompletionStatus                                                                      7C80A7AD 5 Bytes  JMP 00B13FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] Secur32.dll!EncryptMessage                                                                                  77FEA5FB 5 Bytes  JMP 00B11489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] Secur32.dll!DecryptMessage                                                                                  77FEA64A 5 Bytes  JMP 00B12E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] ole32.dll!CoGetClassObject                                                                                  775056C5 5 Bytes  JMP 00B07B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!sendto                                                                                           71A52F51 5 Bytes  JMP 00B145E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!recvfrom                                                                                         71A52FF7 5 Bytes  JMP 00B14335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!closesocket                                                                                      71A53E2B 5 Bytes  JMP 00B12A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!connect                                                                                          71A54A07 5 Bytes  JMP 00B12574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!send                                                                                             71A54C27 5 Bytes  JMP 00B13069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSARecv                                                                                          71A54CB5 5 Bytes  JMP 00B160BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!recv                                                                                             71A5676F 5 Bytes  JMP 00B13A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSASend                                                                                          71A568FA 5 Bytes  JMP 00B135DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSARecvFrom                                                                                      71A5F66A 5 Bytes  JMP 00B163AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSASendTo                                                                                        71A60AAD 5 Bytes  JMP 00B14B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSAConnect                                                                                       71A60C81 5 Bytes  JMP 00B128EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WS2_32.dll!WSAGetOverlappedResult                                                                           71A60D1B 5 Bytes  JMP 00B13CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Winamp\winampa.exe[1004] WININET.dll!UnlockUrlCacheEntryFile                                                                         771C7D3C 5 Bytes  JMP 00B16AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] kernel32.dll!CreateProcessW                                                                7C802336 5 Bytes  JMP 00C05001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] kernel32.dll!GetQueuedCompletionStatus                                                     7C80A7AD 5 Bytes  JMP 00C03FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] Secur32.dll!EncryptMessage                                                                 77FEA5FB 5 Bytes  JMP 00C01489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] Secur32.dll!DecryptMessage                                                                 77FEA64A 5 Bytes  JMP 00C02E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] ole32.dll!CoGetClassObject                                                                 775056C5 5 Bytes  JMP 00BF7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!sendto                                                                          71A52F51 5 Bytes  JMP 00C045E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!recvfrom                                                                        71A52FF7 5 Bytes  JMP 00C04335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!closesocket                                                                     71A53E2B 5 Bytes  JMP 00C02A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!connect                                                                         71A54A07 5 Bytes  JMP 00C02574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!send                                                                            71A54C27 5 Bytes  JMP 00C03069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSARecv                                                                         71A54CB5 5 Bytes  JMP 00C060BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!recv                                                                            71A5676F 5 Bytes  JMP 00C03A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSASend                                                                         71A568FA 5 Bytes  JMP 00C035DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSARecvFrom                                                                     71A5F66A 5 Bytes  JMP 00C063AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSASendTo                                                                       71A60AAD 5 Bytes  JMP 00C04B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSAConnect                                                                      71A60C81 5 Bytes  JMP 00C028EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WS2_32.dll!WSAGetOverlappedResult                                                          71A60D1B 5 Bytes  JMP 00C03CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe[1036] WININET.dll!UnlockUrlCacheEntryFile                                                        771C7D3C 5 Bytes  JMP 00C06AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] kernel32.dll!CreateProcessW                                                                     7C802336 5 Bytes  JMP 03455001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] kernel32.dll!GetQueuedCompletionStatus                                                          7C80A7AD 5 Bytes  JMP 03453FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] Secur32.dll!EncryptMessage                                                                      77FEA5FB 5 Bytes  JMP 03451489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] Secur32.dll!DecryptMessage                                                                      77FEA64A 5 Bytes  JMP 03452E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] ole32.dll!CoGetClassObject                                                                      775056C5 5 Bytes  JMP 03447B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!sendto                                                                               71A52F51 5 Bytes  JMP 034545E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!recvfrom                                                                             71A52FF7 5 Bytes  JMP 03454335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!closesocket                                                                          71A53E2B 5 Bytes  JMP 03452A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!connect                                                                              71A54A07 5 Bytes  JMP 03452574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!send                                                                                 71A54C27 5 Bytes  JMP 03453069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSARecv                                                                              71A54CB5 5 Bytes  JMP 034560BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!recv                                                                                 71A5676F 5 Bytes  JMP 03453A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSASend                                                                              71A568FA 5 Bytes  JMP 034535DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSARecvFrom                                                                          71A5F66A 5 Bytes  JMP 034563AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSASendTo                                                                            71A60AAD 5 Bytes  JMP 03454B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSAConnect                                                                           71A60C81 5 Bytes  JMP 034528EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WS2_32.dll!WSAGetOverlappedResult                                                               71A60D1B 5 Bytes  JMP 03453CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[1356] WININET.dll!UnlockUrlCacheEntryFile                                                             771C7D3C 5 Bytes  JMP 03456AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] kernel32.dll!CreateProcessW                                                                                             7C802336 5 Bytes  JMP 02C95001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] kernel32.dll!GetQueuedCompletionStatus                                                                                  7C80A7AD 5 Bytes  JMP 02C93FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] Secur32.dll!EncryptMessage                                                                                              77FEA5FB 5 Bytes  JMP 02C91489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] Secur32.dll!DecryptMessage                                                                                              77FEA64A 5 Bytes  JMP 02C92E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] ole32.dll!CoGetClassObject                                                                                              775056C5 5 Bytes  JMP 02C87B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WININET.dll!UnlockUrlCacheEntryFile                                                                                     771C7D3C 5 Bytes  JMP 02C96AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!sendto                                                                                                       71A52F51 5 Bytes  JMP 02C945E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!recvfrom                                                                                                     71A52FF7 5 Bytes  JMP 02C94335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!closesocket                                                                                                  71A53E2B 5 Bytes  JMP 02C92A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!connect                                                                                                      71A54A07 5 Bytes  JMP 02C92574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!send                                                                                                         71A54C27 5 Bytes  JMP 02C93069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSARecv                                                                                                      71A54CB5 5 Bytes  JMP 02C960BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!recv                                                                                                         71A5676F 5 Bytes  JMP 02C93A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSASend                                                                                                      71A568FA 5 Bytes  JMP 02C935DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSARecvFrom                                                                                                  71A5F66A 5 Bytes  JMP 02C963AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSASendTo                                                                                                    71A60AAD 5 Bytes  JMP 02C94B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSAConnect                                                                                                   71A60C81 5 Bytes  JMP 02C928EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\Explorer.exe[1512] WS2_32.dll!WSAGetOverlappedResult                                                                                       71A60D1B 5 Bytes  JMP 02C93CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] kernel32.dll!CreateProcessW                                                                7C802336 5 Bytes  JMP 01405001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] kernel32.dll!GetQueuedCompletionStatus                                                     7C80A7AD 5 Bytes  JMP 01403FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] Secur32.dll!EncryptMessage                                                                 77FEA5FB 5 Bytes  JMP 01401489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] Secur32.dll!DecryptMessage                                                                 77FEA64A 5 Bytes  JMP 01402E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] ole32.dll!CoGetClassObject                                                                 775056C5 5 Bytes  JMP 013F7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!sendto                                                                          71A52F51 5 Bytes  JMP 014045E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!recvfrom                                                                        71A52FF7 5 Bytes  JMP 01404335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!closesocket                                                                     71A53E2B 5 Bytes  JMP 01402A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!connect                                                                         71A54A07 5 Bytes  JMP 01402574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!send                                                                            71A54C27 5 Bytes  JMP 01403069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSARecv                                                                         71A54CB5 5 Bytes  JMP 014060BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!recv                                                                            71A5676F 5 Bytes  JMP 01403A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSASend                                                                         71A568FA 5 Bytes  JMP 014035DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSARecvFrom                                                                     71A5F66A 5 Bytes  JMP 014063AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSASendTo                                                                       71A60AAD 5 Bytes  JMP 01404B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSAConnect                                                                      71A60C81 5 Bytes  JMP 014028EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WS2_32.dll!WSAGetOverlappedResult                                                          71A60D1B 5 Bytes  JMP 01403CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe[1720] WININET.dll!UnlockUrlCacheEntryFile                                                        771C7D3C 5 Bytes  JMP 01406AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, EC, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, EF, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, EC, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, ED, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B91C2E8 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, EE, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, ED, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, EE, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B91C359 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, EC, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B91C487 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, ED, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, EE, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, EF, EC, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1780] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] kernel32.dll!CreateProcessW                                                                               7C802336 5 Bytes  JMP 00CD5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] kernel32.dll!GetQueuedCompletionStatus                                                                    7C80A7AD 5 Bytes  JMP 00CD3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] Secur32.dll!EncryptMessage                                                                                77FEA5FB 5 Bytes  JMP 00CD1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] Secur32.dll!DecryptMessage                                                                                77FEA64A 5 Bytes  JMP 00CD2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] ole32.dll!CoGetClassObject                                                                                775056C5 5 Bytes  JMP 00CC7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!sendto                                                                                         71A52F51 5 Bytes  JMP 00CD45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!recvfrom                                                                                       71A52FF7 5 Bytes  JMP 00CD4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!closesocket                                                                                    71A53E2B 5 Bytes  JMP 00CD2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!connect                                                                                        71A54A07 5 Bytes  JMP 00CD2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!send                                                                                           71A54C27 5 Bytes  JMP 00CD3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSARecv                                                                                        71A54CB5 5 Bytes  JMP 00CD60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!recv                                                                                           71A5676F 5 Bytes  JMP 00CD3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSASend                                                                                        71A568FA 5 Bytes  JMP 00CD35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSARecvFrom                                                                                    71A5F66A 5 Bytes  JMP 00CD63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSASendTo                                                                                      71A60AAD 5 Bytes  JMP 00CD4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSAConnect                                                                                     71A60C81 5 Bytes  JMP 00CD28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WS2_32.dll!WSAGetOverlappedResult                                                                         71A60D1B 5 Bytes  JMP 00CD3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\wbem\unsecapp.exe[2000] WININET.dll!UnlockUrlCacheEntryFile                                                                       771C7D3C 5 Bytes  JMP 00CD6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] kernel32.dll!CreateProcessW                                                                 7C802336 5 Bytes  JMP 00C95001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] kernel32.dll!GetQueuedCompletionStatus                                                      7C80A7AD 5 Bytes  JMP 00C93FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] Secur32.dll!EncryptMessage                                                                  77FEA5FB 5 Bytes  JMP 00C91489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] Secur32.dll!DecryptMessage                                                                  77FEA64A 5 Bytes  JMP 00C92E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] ole32.dll!CoGetClassObject                                                                  775056C5 5 Bytes  JMP 00C87B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WININET.dll!UnlockUrlCacheEntryFile                                                         771C7D3C 5 Bytes  JMP 00C96AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!sendto                                                                           71A52F51 5 Bytes  JMP 00C945E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!recvfrom                                                                         71A52FF7 5 Bytes  JMP 00C94335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!closesocket                                                                      71A53E2B 5 Bytes  JMP 00C92A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!connect                                                                          71A54A07 5 Bytes  JMP 00C92574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!send                                                                             71A54C27 5 Bytes  JMP 00C93069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSARecv                                                                          71A54CB5 5 Bytes  JMP 00C960BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!recv                                                                             71A5676F 5 Bytes  JMP 00C93A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSASend                                                                          71A568FA 5 Bytes  JMP 00C935DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSARecvFrom                                                                      71A5F66A 5 Bytes  JMP 00C963AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSASendTo                                                                        71A60AAD 5 Bytes  JMP 00C94B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSAConnect                                                                       71A60C81 5 Bytes  JMP 00C928EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Search Settings\SearchSettings.exe[2204] WS2_32.dll!WSAGetOverlappedResult                                                           71A60D1B 5 Bytes  JMP 00C93CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] kernel32.dll!CreateProcessW                                                                             7C802336 5 Bytes  JMP 01B15001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] kernel32.dll!GetQueuedCompletionStatus                                                                  7C80A7AD 5 Bytes  JMP 01B13FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!sendto                                                                                       71A52F51 5 Bytes  JMP 01B145E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!recvfrom                                                                                     71A52FF7 5 Bytes  JMP 01B14335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!closesocket                                                                                  71A53E2B 5 Bytes  JMP 01B12A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!connect                                                                                      71A54A07 5 Bytes  JMP 01B12574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!send                                                                                         71A54C27 5 Bytes  JMP 01B13069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSARecv                                                                                      71A54CB5 5 Bytes  JMP 01B160BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!recv                                                                                         71A5676F 5 Bytes  JMP 01B13A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSASend                                                                                      71A568FA 5 Bytes  JMP 01B135DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSARecvFrom                                                                                  71A5F66A 5 Bytes  JMP 01B163AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSASendTo                                                                                    71A60AAD 5 Bytes  JMP 01B14B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSAConnect                                                                                   71A60C81 5 Bytes  JMP 01B128EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WS2_32.dll!WSAGetOverlappedResult                                                                       71A60D1B 5 Bytes  JMP 01B13CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] Secur32.dll!EncryptMessage                                                                              77FEA5FB 5 Bytes  JMP 01B11489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] Secur32.dll!DecryptMessage                                                                              77FEA64A 5 Bytes  JMP 01B12E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] ole32.dll!CoGetClassObject                                                                              775056C5 5 Bytes  JMP 01B07B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe[2216] WININET.dll!UnlockUrlCacheEntryFile                                                                     771C7D3C 5 Bytes  JMP 01B16AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] kernel32.dll!CreateProcessW                                                                      7C802336 5 Bytes  JMP 010A5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] kernel32.dll!GetQueuedCompletionStatus                                                           7C80A7AD 5 Bytes  JMP 010A3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WININET.dll!UnlockUrlCacheEntryFile                                                              771C7D3C 5 Bytes  JMP 010A6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] Secur32.dll!EncryptMessage                                                                       77FEA5FB 5 Bytes  JMP 010A1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] Secur32.dll!DecryptMessage                                                                       77FEA64A 5 Bytes  JMP 010A2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] ole32.dll!CoGetClassObject                                                                       775056C5 5 Bytes  JMP 01097B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!sendto                                                                                71A52F51 5 Bytes  JMP 010A45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!recvfrom                                                                              71A52FF7 5 Bytes  JMP 010A4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!closesocket                                                                           71A53E2B 5 Bytes  JMP 010A2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!connect                                                                               71A54A07 5 Bytes  JMP 010A2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!send                                                                                  71A54C27 5 Bytes  JMP 010A3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSARecv                                                                               71A54CB5 5 Bytes  JMP 010A60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!recv                                                                                  71A5676F 5 Bytes  JMP 010A3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSASend                                                                               71A568FA 5 Bytes  JMP 010A35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSARecvFrom                                                                           71A5F66A 5 Bytes  JMP 010A63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSASendTo                                                                             71A60AAD 5 Bytes  JMP 010A4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSAConnect                                                                            71A60C81 5 Bytes  JMP 010A28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\SweetIM\Messenger\SweetIM.exe[2236] WS2_32.dll!WSAGetOverlappedResult                                                                71A60D1B 5 Bytes  JMP 010A3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] kernel32.dll!CreateProcessW                                                                7C802336 5 Bytes  JMP 00BA5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] kernel32.dll!GetQueuedCompletionStatus                                                     7C80A7AD 5 Bytes  JMP 00BA3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] Secur32.dll!EncryptMessage                                                                 77FEA5FB 5 Bytes  JMP 00BA1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] Secur32.dll!DecryptMessage                                                                 77FEA64A 5 Bytes  JMP 00BA2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] ole32.dll!CoGetClassObject                                                                 775056C5 5 Bytes  JMP 00B97B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!sendto                                                                          71A52F51 5 Bytes  JMP 00BA45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!recvfrom                                                                        71A52FF7 5 Bytes  JMP 00BA4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!closesocket                                                                     71A53E2B 5 Bytes  JMP 00BA2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!connect                                                                         71A54A07 5 Bytes  JMP 00BA2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!send                                                                            71A54C27 5 Bytes  JMP 00BA3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSARecv                                                                         71A54CB5 5 Bytes  JMP 00BA60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!recv                                                                            71A5676F 5 Bytes  JMP 00BA3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSASend                                                                         71A568FA 5 Bytes  JMP 00BA35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSARecvFrom                                                                     71A5F66A 5 Bytes  JMP 00BA63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSASendTo                                                                       71A60AAD 5 Bytes  JMP 00BA4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSAConnect                                                                      71A60C81 5 Bytes  JMP 00BA28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WS2_32.dll!WSAGetOverlappedResult                                                          71A60D1B 5 Bytes  JMP 00BA3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[2244] WININET.dll!UnlockUrlCacheEntryFile                                                        771C7D3C 5 Bytes  JMP 00BA6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] kernel32.dll!CreateProcessW                                                               7C802336 5 Bytes  JMP 01205001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] kernel32.dll!GetQueuedCompletionStatus                                                    7C80A7AD 5 Bytes  JMP 01203FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] ole32.dll!CoGetClassObject                                                                775056C5 5 Bytes  JMP 011F7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] Secur32.dll!EncryptMessage                                                                77FEA5FB 5 Bytes  JMP 01201489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] Secur32.dll!DecryptMessage                                                                77FEA64A 5 Bytes  JMP 01202E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!sendto                                                                         71A52F51 5 Bytes  JMP 012045E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!recvfrom                                                                       71A52FF7 5 Bytes  JMP 01204335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!closesocket                                                                    71A53E2B 5 Bytes  JMP 01202A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!connect                                                                        71A54A07 5 Bytes  JMP 01202574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!send                                                                           71A54C27 5 Bytes  JMP 01203069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSARecv                                                                        71A54CB5 5 Bytes  JMP 012060BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!recv                                                                           71A5676F 5 Bytes  JMP 01203A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSASend                                                                        71A568FA 5 Bytes  JMP 012035DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSARecvFrom                                                                    71A5F66A 5 Bytes  JMP 012063AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSASendTo                                                                      71A60AAD 5 Bytes  JMP 01204B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSAConnect                                                                     71A60C81 5 Bytes  JMP 012028EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WS2_32.dll!WSAGetOverlappedResult                                                         71A60D1B 5 Bytes  JMP 01203CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe[2264] WININET.dll!UnlockUrlCacheEntryFile                                                       771C7D3C 5 Bytes  JMP 01206AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] kernel32.dll!CreateProcessW                                                                                    7C802336 5 Bytes  JMP 01055001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] kernel32.dll!GetQueuedCompletionStatus                                                                         7C80A7AD 5 Bytes  JMP 01053FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] Secur32.dll!EncryptMessage                                                                                     77FEA5FB 5 Bytes  JMP 01051489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] Secur32.dll!DecryptMessage                                                                                     77FEA64A 5 Bytes  JMP 01052E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] ole32.dll!CoGetClassObject                                                                                     775056C5 5 Bytes  JMP 01047B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!sendto                                                                                              71A52F51 5 Bytes  JMP 010545E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!recvfrom                                                                                            71A52FF7 5 Bytes  JMP 01054335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!closesocket                                                                                         71A53E2B 5 Bytes  JMP 01052A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!connect                                                                                             71A54A07 5 Bytes  JMP 01052574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!send                                                                                                71A54C27 5 Bytes  JMP 01053069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSARecv                                                                                             71A54CB5 5 Bytes  JMP 010560BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!recv                                                                                                71A5676F 5 Bytes  JMP 01053A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSASend                                                                                             71A568FA 5 Bytes  JMP 010535DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSARecvFrom                                                                                         71A5F66A 5 Bytes  JMP 010563AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSASendTo                                                                                           71A60AAD 5 Bytes  JMP 01054B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSAConnect                                                                                          71A60C81 5 Bytes  JMP 010528EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WS2_32.dll!WSAGetOverlappedResult                                                                              71A60D1B 5 Bytes  JMP 01053CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\RUNDLL32.EXE[2344] WININET.dll!UnlockUrlCacheEntryFile                                                                            771C7D3C 5 Bytes  JMP 01056AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] kernel32.dll!CreateProcessW                                                        7C802336 5 Bytes  JMP 00DF5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] kernel32.dll!GetQueuedCompletionStatus                                             7C80A7AD 5 Bytes  JMP 00DF3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] Secur32.dll!EncryptMessage                                                         77FEA5FB 5 Bytes  JMP 00DF1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] Secur32.dll!DecryptMessage                                                         77FEA64A 5 Bytes  JMP 00DF2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] ole32.dll!CoGetClassObject                                                         775056C5 5 Bytes  JMP 00DE7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WININET.dll!UnlockUrlCacheEntryFile                                                771C7D3C 5 Bytes  JMP 00DF6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!sendto                                                                  71A52F51 5 Bytes  JMP 00DF45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!recvfrom                                                                71A52FF7 5 Bytes  JMP 00DF4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!closesocket                                                             71A53E2B 5 Bytes  JMP 00DF2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!connect                                                                 71A54A07 5 Bytes  JMP 00DF2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!send                                                                    71A54C27 5 Bytes  JMP 00DF3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSARecv                                                                 71A54CB5 5 Bytes  JMP 00DF60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!recv                                                                    71A5676F 5 Bytes  JMP 00DF3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSASend                                                                 71A568FA 5 Bytes  JMP 00DF35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSARecvFrom                                                             71A5F66A 5 Bytes  JMP 00DF63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSASendTo                                                               71A60AAD 5 Bytes  JMP 00DF4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSAConnect                                                              71A60C81 5 Bytes  JMP 00DF28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[2368] WS2_32.dll!WSAGetOverlappedResult                                                  71A60D1B 5 Bytes  JMP 00DF3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] kernel32.dll!CreateProcessW                                                                                      7C802336 5 Bytes  JMP 00BC5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] kernel32.dll!GetQueuedCompletionStatus                                                                           7C80A7AD 5 Bytes  JMP 00BC3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] Secur32.dll!EncryptMessage                                                                                       77FEA5FB 5 Bytes  JMP 00BC1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] Secur32.dll!DecryptMessage                                                                                       77FEA64A 5 Bytes  JMP 00BC2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] ole32.dll!CoGetClassObject                                                                                       775056C5 5 Bytes  JMP 00BB7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!sendto                                                                                                71A52F51 5 Bytes  JMP 00BC45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!recvfrom                                                                                              71A52FF7 5 Bytes  JMP 00BC4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!closesocket                                                                                           71A53E2B 5 Bytes  JMP 00BC2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!connect                                                                                               71A54A07 5 Bytes  JMP 00BC2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!send                                                                                                  71A54C27 5 Bytes  JMP 00BC3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSARecv                                                                                               71A54CB5 5 Bytes  JMP 00BC60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!recv                                                                                                  71A5676F 5 Bytes  JMP 00BC3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSASend                                                                                               71A568FA 5 Bytes  JMP 00BC35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSARecvFrom                                                                                           71A5F66A 5 Bytes  JMP 00BC63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSASendTo                                                                                             71A60AAD 5 Bytes  JMP 00BC4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSAConnect                                                                                            71A60C81 5 Bytes  JMP 00BC28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WS2_32.dll!WSAGetOverlappedResult                                                                                71A60D1B 5 Bytes  JMP 00BC3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\ctfmon.exe[2376] WININET.dll!UnlockUrlCacheEntryFile                                                                              771C7D3C 5 Bytes  JMP 00BC6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] kernel32.dll!CreateProcessW                                                                                  7C802336 5 Bytes  JMP 01FE5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] kernel32.dll!GetQueuedCompletionStatus                                                                       7C80A7AD 5 Bytes  JMP 01FE3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] Secur32.dll!EncryptMessage                                                                                   77FEA5FB 5 Bytes  JMP 01FE1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] Secur32.dll!DecryptMessage                                                                                   77FEA64A 5 Bytes  JMP 01FE2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] ole32.dll!CoGetClassObject                                                                                   775056C5 5 Bytes  JMP 01FD7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!sendto                                                                                            71A52F51 5 Bytes  JMP 01FE45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!recvfrom                                                                                          71A52FF7 5 Bytes  JMP 01FE4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!closesocket                                                                                       71A53E2B 5 Bytes  JMP 01FE2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!connect                                                                                           71A54A07 5 Bytes  JMP 01FE2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!send                                                                                              71A54C27 5 Bytes  JMP 01FE3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSARecv                                                                                           71A54CB5 5 Bytes  JMP 01FE60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!recv                                                                                              71A5676F 5 Bytes  JMP 01FE3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSASend                                                                                           71A568FA 5 Bytes  JMP 01FE35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSARecvFrom                                                                                       71A5F66A 5 Bytes  JMP 01FE63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSASendTo                                                                                         71A60AAD 5 Bytes  JMP 01FE4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSAConnect                                                                                        71A60C81 5 Bytes  JMP 01FE28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WS2_32.dll!WSAGetOverlappedResult                                                                            71A60D1B 5 Bytes  JMP 01FE3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Vtune\TBPanel.exe[2460] WININET.dll!UnlockUrlCacheEntryFile                                                                          771C7D3C 5 Bytes  JMP 01FE6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] kernel32.dll!CreateProcessW              7C802336 5 Bytes  JMP 01AF5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] kernel32.dll!GetQueuedCompletionStatus   7C80A7AD 5 Bytes  JMP 01AF3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] Secur32.dll!EncryptMessage               77FEA5FB 5 Bytes  JMP 01AF1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] Secur32.dll!DecryptMessage               77FEA64A 5 Bytes  JMP 01AF2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] ole32.dll!CoGetClassObject               775056C5 5 Bytes  JMP 01AE7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!sendto                        71A52F51 5 Bytes  JMP 01AF45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!recvfrom                      71A52FF7 5 Bytes  JMP 01AF4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!closesocket                   71A53E2B 5 Bytes  JMP 01AF2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!connect                       71A54A07 5 Bytes  JMP 01AF2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!send                          71A54C27 5 Bytes  JMP 01AF3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSARecv                       71A54CB5 5 Bytes  JMP 01AF60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!recv                          71A5676F 5 Bytes  JMP 01AF3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSASend                       71A568FA 5 Bytes  JMP 01AF35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSARecvFrom                   71A5F66A 5 Bytes  JMP 01AF63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSASendTo                     71A60AAD 5 Bytes  JMP 01AF4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSAConnect                    71A60C81 5 Bytes  JMP 01AF28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WS2_32.dll!WSAGetOverlappedResult        71A60D1B 5 Bytes  JMP 01AF3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2468] WININET.dll!UnlockUrlCacheEntryFile      771C7D3C 5 Bytes  JMP 01AF6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, A0, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, A3, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, A0, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, A1, C5, 00] {TEST AL, 0xa1; LDS EAX, DWORD [EAX]}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B919B9C 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, A2, C5, 00] {TEST AL, 0xa2; LDS EAX, DWORD [EAX]}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, A1, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, A2, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B919C0D 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, A0, C5, 00] {TEST AL, 0xa0; LDS EAX, DWORD [EAX]}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B919D3B 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, A1, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, A2, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, A3, C5, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2500] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] kernel32.dll!CreateProcessW                                                                                    7C802336 5 Bytes  JMP 00F75001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] kernel32.dll!GetQueuedCompletionStatus                                                                         7C80A7AD 5 Bytes  JMP 00F73FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] Secur32.dll!EncryptMessage                                                                                     77FEA5FB 5 Bytes  JMP 00F71489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] Secur32.dll!DecryptMessage                                                                                     77FEA64A 5 Bytes  JMP 00F72E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] ole32.dll!CoGetClassObject                                                                                     775056C5 5 Bytes  JMP 00F67B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!sendto                                                                                              71A52F51 5 Bytes  JMP 00F745E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!recvfrom                                                                                            71A52FF7 5 Bytes  JMP 00F74335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!closesocket                                                                                         71A53E2B 5 Bytes  JMP 00F72A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!connect                                                                                             71A54A07 5 Bytes  JMP 00F72574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!send                                                                                                71A54C27 5 Bytes  JMP 00F73069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSARecv                                                                                             71A54CB5 5 Bytes  JMP 00F760BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!recv                                                                                                71A5676F 5 Bytes  JMP 00F73A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSASend                                                                                             71A568FA 5 Bytes  JMP 00F735DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSARecvFrom                                                                                         71A5F66A 5 Bytes  JMP 00F763AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSASendTo                                                                                           71A60AAD 5 Bytes  JMP 00F74B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSAConnect                                                                                          71A60C81 5 Bytes  JMP 00F728EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WS2_32.dll!WSAGetOverlappedResult                                                                              71A60D1B 5 Bytes  JMP 00F73CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\WINDOWS\system32\rundll32.exe[2556] WININET.dll!UnlockUrlCacheEntryFile                                                                            771C7D3C 5 Bytes  JMP 00F76AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] kernel32.dll!CreateProcessW                                                                               7C802336 5 Bytes  JMP 01395001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] kernel32.dll!GetQueuedCompletionStatus                                                                    7C80A7AD 5 Bytes  JMP 01393FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] Secur32.dll!EncryptMessage                                                                                77FEA5FB 5 Bytes  JMP 01391489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] Secur32.dll!DecryptMessage                                                                                77FEA64A 5 Bytes  JMP 01392E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!sendto                                                                                         71A52F51 5 Bytes  JMP 013945E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!recvfrom                                                                                       71A52FF7 5 Bytes  JMP 01394335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!closesocket                                                                                    71A53E2B 5 Bytes  JMP 01392A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!connect                                                                                        71A54A07 5 Bytes  JMP 01392574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!send                                                                                           71A54C27 5 Bytes  JMP 01393069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSARecv                                                                                        71A54CB5 5 Bytes  JMP 013960BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!recv                                                                                           71A5676F 5 Bytes  JMP 01393A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSASend                                                                                        71A568FA 5 Bytes  JMP 013935DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSARecvFrom                                                                                    71A5F66A 5 Bytes  JMP 013963AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSASendTo                                                                                      71A60AAD 5 Bytes  JMP 01394B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSAConnect                                                                                     71A60C81 5 Bytes  JMP 013928EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WS2_32.dll!WSAGetOverlappedResult                                                                         71A60D1B 5 Bytes  JMP 01393CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] ole32.dll!CoGetClassObject                                                                                775056C5 5 Bytes  JMP 01387B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Messenger\msmsgs.exe[2620] WININET.dll!UnlockUrlCacheEntryFile                                                                       771C7D3C 5 Bytes  JMP 01396AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] kernel32.dll!CreateProcessW                                                       7C802336 5 Bytes  JMP 018F5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] kernel32.dll!GetQueuedCompletionStatus                                            7C80A7AD 5 Bytes  JMP 018F3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] Secur32.dll!EncryptMessage                                                        77FEA5FB 5 Bytes  JMP 018F1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] Secur32.dll!DecryptMessage                                                        77FEA64A 5 Bytes  JMP 018F2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] ole32.dll!CoGetClassObject                                                        775056C5 5 Bytes  JMP 018E7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!sendto                                                                 71A52F51 5 Bytes  JMP 018F45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!recvfrom                                                               71A52FF7 5 Bytes  JMP 018F4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!closesocket                                                            71A53E2B 5 Bytes  JMP 018F2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!connect                                                                71A54A07 5 Bytes  JMP 018F2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!send                                                                   71A54C27 5 Bytes  JMP 018F3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSARecv                                                                71A54CB5 5 Bytes  JMP 018F60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!recv                                                                   71A5676F 5 Bytes  JMP 018F3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSASend                                                                71A568FA 5 Bytes  JMP 018F35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSARecvFrom                                                            71A5F66A 5 Bytes  JMP 018F63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSASendTo                                                              71A60AAD 5 Bytes  JMP 018F4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSAConnect                                                             71A60C81 5 Bytes  JMP 018F28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WS2_32.dll!WSAGetOverlappedResult                                                 71A60D1B 5 Bytes  JMP 018F3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[2668] WININET.dll!UnlockUrlCacheEntryFile                                               771C7D3C 5 Bytes  JMP 018F6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] kernel32.dll!CreateProcessW                                                                            7C802336 5 Bytes  JMP 03925001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] kernel32.dll!GetQueuedCompletionStatus                                                                 7C80A7AD 5 Bytes  JMP 03923FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] ole32.dll!CoGetClassObject                                                                             775056C5 5 Bytes  JMP 03917B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] Secur32.dll!EncryptMessage                                                                             77FEA5FB 5 Bytes  JMP 03921489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] Secur32.dll!DecryptMessage                                                                             77FEA64A 5 Bytes  JMP 03922E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!sendto                                                                                      71A52F51 5 Bytes  JMP 039245E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!recvfrom                                                                                    71A52FF7 5 Bytes  JMP 03924335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!closesocket                                                                                 71A53E2B 5 Bytes  JMP 03922A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!connect                                                                                     71A54A07 5 Bytes  JMP 03922574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!send                                                                                        71A54C27 5 Bytes  JMP 03923069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSARecv                                                                                     71A54CB5 5 Bytes  JMP 039260BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!recv                                                                                        71A5676F 5 Bytes  JMP 03923A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSASend                                                                                     71A568FA 5 Bytes  JMP 039235DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSARecvFrom                                                                                 71A5F66A 5 Bytes  JMP 039263AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSASendTo                                                                                   71A60AAD 5 Bytes  JMP 03924B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSAConnect                                                                                  71A60C81 5 Bytes  JMP 039228EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WS2_32.dll!WSAGetOverlappedResult                                                                      71A60D1B 5 Bytes  JMP 03923CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\Vid HD\Vid.exe[2844] WININET.dll!UnlockUrlCacheEntryFile                                                                    771C7D3C 5 Bytes  JMP 03926AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, 6C, 04, 01] {SUB [ESP+EAX+0x1], CH}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, 6F, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, 6C, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, 6D, 04, 01] {TEST AL, 0x6d; ADD AL, 0x1}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B91DA68 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, 6E, 04, 01] {TEST AL, 0x6e; ADD AL, 0x1}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, 6D, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, 6E, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B91DAD9 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, 6C, 04, 01] {TEST AL, 0x6c; ADD AL, 0x1}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B91DC07 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, 6D, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, 6E, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, 6F, 04, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3168] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] kernel32.dll!CreateProcessW                                                                7C802336 5 Bytes  JMP 00BD5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] kernel32.dll!GetQueuedCompletionStatus                                                     7C80A7AD 5 Bytes  JMP 00BD3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] Secur32.dll!EncryptMessage                                                                 77FEA5FB 5 Bytes  JMP 00BD1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] Secur32.dll!DecryptMessage                                                                 77FEA64A 5 Bytes  JMP 00BD2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] ole32.dll!CoGetClassObject                                                                 775056C5 5 Bytes  JMP 00BC7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!sendto                                                                          71A52F51 5 Bytes  JMP 00BD45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!recvfrom                                                                        71A52FF7 5 Bytes  JMP 00BD4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!closesocket                                                                     71A53E2B 5 Bytes  JMP 00BD2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!connect                                                                         71A54A07 5 Bytes  JMP 00BD2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!send                                                                            71A54C27 5 Bytes  JMP 00BD3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSARecv                                                                         71A54CB5 5 Bytes  JMP 00BD60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!recv                                                                            71A5676F 5 Bytes  JMP 00BD3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSASend                                                                         71A568FA 5 Bytes  JMP 00BD35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSARecvFrom                                                                     71A5F66A 5 Bytes  JMP 00BD63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSASendTo                                                                       71A60AAD 5 Bytes  JMP 00BD4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSAConnect                                                                      71A60C81 5 Bytes  JMP 00BD28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WS2_32.dll!WSAGetOverlappedResult                                                          71A60D1B 5 Bytes  JMP 00BD3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3280] WININET.dll!UnlockUrlCacheEntryFile                                                        771C7D3C 5 Bytes  JMP 00BD6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] kernel32.dll!CreateProcessW                                                               7C802336 5 Bytes  JMP 00D45001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] kernel32.dll!GetQueuedCompletionStatus                                                    7C80A7AD 5 Bytes  JMP 00D43FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] Secur32.dll!EncryptMessage                                                                77FEA5FB 5 Bytes  JMP 00D41489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] Secur32.dll!DecryptMessage                                                                77FEA64A 5 Bytes  JMP 00D42E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] ole32.dll!CoGetClassObject                                                                775056C5 5 Bytes  JMP 00D37B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!sendto                                                                         71A52F51 5 Bytes  JMP 00D445E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!recvfrom                                                                       71A52FF7 5 Bytes  JMP 00D44335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!closesocket                                                                    71A53E2B 5 Bytes  JMP 00D42A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!connect                                                                        71A54A07 5 Bytes  JMP 00D42574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!send                                                                           71A54C27 5 Bytes  JMP 00D43069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSARecv                                                                        71A54CB5 5 Bytes  JMP 00D460BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!recv                                                                           71A5676F 5 Bytes  JMP 00D43A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSASend                                                                        71A568FA 5 Bytes  JMP 00D435DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSARecvFrom                                                                    71A5F66A 5 Bytes  JMP 00D463AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSASendTo                                                                      71A60AAD 5 Bytes  JMP 00D44B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSAConnect                                                                     71A60C81 5 Bytes  JMP 00D428EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WS2_32.dll!WSAGetOverlappedResult                                                         71A60D1B 5 Bytes  JMP 00D43CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\DOCUME~1\Darek\USTAWI~1\Temp\Rar$EX00.188\gmer.exe[3360] WININET.dll!UnlockUrlCacheEntryFile                                                       771C7D3C 5 Bytes  JMP 00D46AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] kernel32.dll!CreateProcessW                                                                7C802336 5 Bytes  JMP 01415001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] kernel32.dll!GetQueuedCompletionStatus                                                     7C80A7AD 5 Bytes  JMP 01413FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] Secur32.dll!EncryptMessage                                                                 77FEA5FB 5 Bytes  JMP 01411489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] Secur32.dll!DecryptMessage                                                                 77FEA64A 5 Bytes  JMP 01412E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] ole32.dll!CoGetClassObject                                                                 775056C5 5 Bytes  JMP 01407B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!sendto                                                                          71A52F51 5 Bytes  JMP 014145E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!recvfrom                                                                        71A52FF7 5 Bytes  JMP 01414335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!closesocket                                                                     71A53E2B 5 Bytes  JMP 01412A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!connect                                                                         71A54A07 5 Bytes  JMP 01412574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!send                                                                            71A54C27 5 Bytes  JMP 01413069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSARecv                                                                         71A54CB5 5 Bytes  JMP 014160BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!recv                                                                            71A5676F 5 Bytes  JMP 01413A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSASend                                                                         71A568FA 5 Bytes  JMP 014135DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSARecvFrom                                                                     71A5F66A 5 Bytes  JMP 014163AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSASendTo                                                                       71A60AAD 5 Bytes  JMP 01414B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSAConnect                                                                      71A60C81 5 Bytes  JMP 014128EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WS2_32.dll!WSAGetOverlappedResult                                                          71A60D1B 5 Bytes  JMP 01413CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[3584] WININET.dll!UnlockUrlCacheEntryFile                                                        771C7D3C 5 Bytes  JMP 01416AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] kernel32.dll!CreateProcessW                                                 7C802336 5 Bytes  JMP 02665001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] kernel32.dll!GetQueuedCompletionStatus                                      7C80A7AD 5 Bytes  JMP 02663FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] ole32.dll!CoGetClassObject                                                  775056C5 5 Bytes  JMP 02657B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] Secur32.dll!EncryptMessage                                                  77FEA5FB 5 Bytes  JMP 02661489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] Secur32.dll!DecryptMessage                                                  77FEA64A 5 Bytes  JMP 02662E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!sendto                                                           71A52F51 5 Bytes  JMP 026645E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!recvfrom                                                         71A52FF7 5 Bytes  JMP 02664335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!closesocket                                                      71A53E2B 5 Bytes  JMP 02662A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!connect                                                          71A54A07 5 Bytes  JMP 02662574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!send                                                             71A54C27 5 Bytes  JMP 02663069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSARecv                                                          71A54CB5 5 Bytes  JMP 026660BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!recv                                                             71A5676F 5 Bytes  JMP 02663A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSASend                                                          71A568FA 5 Bytes  JMP 026635DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSARecvFrom                                                      71A5F66A 5 Bytes  JMP 026663AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSASendTo                                                        71A60AAD 5 Bytes  JMP 02664B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSAConnect                                                       71A60C81 5 Bytes  JMP 026628EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WS2_32.dll!WSAGetOverlappedResult                                           71A60D1B 5 Bytes  JMP 02663CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe[3736] WININET.dll!UnlockUrlCacheEntryFile                                         771C7D3C 5 Bytes  JMP 02666AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] kernel32.dll!CreateProcessW                                                                             7C802336 5 Bytes  JMP 022E5001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] kernel32.dll!GetQueuedCompletionStatus                                                                  7C80A7AD 5 Bytes  JMP 022E3FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] Secur32.dll!EncryptMessage                                                                              77FEA5FB 5 Bytes  JMP 022E1489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] Secur32.dll!DecryptMessage                                                                              77FEA64A 5 Bytes  JMP 022E2E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!sendto                                                                                       71A52F51 5 Bytes  JMP 022E45E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!recvfrom                                                                                     71A52FF7 5 Bytes  JMP 022E4335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!closesocket                                                                                  71A53E2B 5 Bytes  JMP 022E2A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!connect                                                                                      71A54A07 5 Bytes  JMP 022E2574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!send                                                                                         71A54C27 5 Bytes  JMP 022E3069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSARecv                                                                                      71A54CB5 5 Bytes  JMP 022E60BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!recv                                                                                         71A5676F 5 Bytes  JMP 022E3A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSASend                                                                                      71A568FA 5 Bytes  JMP 022E35DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSARecvFrom                                                                                  71A5F66A 5 Bytes  JMP 022E63AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSASendTo                                                                                    71A60AAD 5 Bytes  JMP 022E4B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSAConnect                                                                                   71A60C81 5 Bytes  JMP 022E28EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WS2_32.dll!WSAGetOverlappedResult                                                                       71A60D1B 5 Bytes  JMP 022E3CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] ole32.dll!CoGetClassObject                                                                              775056C5 5 Bytes  JMP 022D7B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Program Files\EDIMAX\Common\RaUI.exe[3812] WININET.dll!UnlockUrlCacheEntryFile                                                                     771C7D3C 5 Bytes  JMP 022E6AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, 28, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, 2B, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, 28, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, 29, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B90EC24 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, 2A, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, 29, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, 2A, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B90EC95 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, 28, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B90EDC3 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, 29, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, 2A, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, 2B, 16, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] kernel32.dll!CreateProcessW              7C802336 5 Bytes  JMP 01A65001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] kernel32.dll!GetQueuedCompletionStatus   7C80A7AD 5 Bytes  JMP 01A63FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] Secur32.dll!EncryptMessage               77FEA5FB 5 Bytes  JMP 01A61489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] Secur32.dll!DecryptMessage               77FEA64A 5 Bytes  JMP 01A62E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] ole32.dll!CoGetClassObject               775056C5 5 Bytes  JMP 01A57B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!sendto                        71A52F51 5 Bytes  JMP 01A645E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!recvfrom                      71A52FF7 5 Bytes  JMP 01A64335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!closesocket                   71A53E2B 5 Bytes  JMP 01A62A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!connect                       71A54A07 5 Bytes  JMP 01A62574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!send                          71A54C27 5 Bytes  JMP 01A63069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSARecv                       71A54CB5 5 Bytes  JMP 01A660BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!recv                          71A5676F 5 Bytes  JMP 01A63A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSASend                       71A568FA 5 Bytes  JMP 01A635DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSARecvFrom                   71A5F66A 5 Bytes  JMP 01A663AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSASendTo                     71A60AAD 5 Bytes  JMP 01A64B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSAConnect                    71A60C81 5 Bytes  JMP 01A628EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WS2_32.dll!WSAGetOverlappedResult        71A60D1B 5 Bytes  JMP 01A63CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5112] WININET.dll!UnlockUrlCacheEntryFile      771C7D3C 5 Bytes  JMP 01A66AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, 0C, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, 0F, 8C, 00] {SUB [EDI], CL; MOV WORD [EAX], ES}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, 0C, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, 0D, 8C, 00] {TEST AL, 0xd; MOV WORD [EAX], ES}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B916208 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, 0E, 8C, 00] {TEST AL, 0xe; MOV WORD [EAX], ES}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, 0D, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, 0E, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B916279 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, 0C, 8C, 00] {TEST AL, 0xc; MOV WORD [EAX], ES}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B9163A7 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, 0D, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, 0E, 8C, 00] {SUB [ESI], CL; MOV WORD [EAX], ES}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, 0F, 8C, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5188] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, A4, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, A7, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, A4, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, A5, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B912BA0 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, A6, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, A5, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, A6, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B912C11 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, A4, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B912D3F 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, A5, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, A6, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, A7, 55, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5236] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, E4, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, E7, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, E4, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, E5, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B91DCE0 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, E6, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, E5, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, E6, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B91DD51 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, E4, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B91DE7F 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, E5, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, E6, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, E7, 06, 01]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5404] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtCreateFile + 6               7C90D096 4 Bytes  [28, 44, A7, 00] {SUB [EDI+0x0], AL}
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtCreateFile + B               7C90D09B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtMapViewOfSection + 6         7C90D506 4 Bytes  [28, 47, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtMapViewOfSection + B         7C90D50B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenFile + 6                 7C90D586 4 Bytes  [68, 44, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenFile + B                 7C90D58B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcess + 6              7C90D5E6 4 Bytes  [A8, 45, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcess + B              7C90D5EB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcessToken + 6         7C90D5F6 4 Bytes  CALL 7B917D40 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcessToken + B         7C90D5FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D606 4 Bytes  [A8, 46, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenProcessTokenEx + B       7C90D60B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThread + 6               7C90D646 4 Bytes  [68, 45, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThread + B               7C90D64B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThreadToken + 6          7C90D656 4 Bytes  [68, 46, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThreadToken + B          7C90D65B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D666 4 Bytes  CALL 7B917DB1 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtOpenThreadTokenEx + B        7C90D66B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtQueryAttributesFile + 6      7C90D6F6 4 Bytes  [A8, 44, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtQueryAttributesFile + B      7C90D6FB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D796 4 Bytes  CALL 7B917EDF 
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtQueryFullAttributesFile + B  7C90D79B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtSetInformationFile + 6       7C90DC46 4 Bytes  [28, 45, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtSetInformationFile + B       7C90DC4B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtSetInformationThread + 6     7C90DC96 4 Bytes  [28, 46, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtSetInformationThread + B     7C90DC9B 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtUnmapViewOfSection + 6       7C90DEF6 4 Bytes  [68, 47, A7, 00]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ntdll.dll!NtUnmapViewOfSection + B       7C90DEFB 1 Byte  [E2]
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] kernel32.dll!CreateProcessW              7C802336 5 Bytes  JMP 04E65001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] kernel32.dll!GetQueuedCompletionStatus   7C80A7AD 5 Bytes  JMP 04E63FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] Secur32.dll!EncryptMessage               77FEA5FB 5 Bytes  JMP 04E61489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] Secur32.dll!DecryptMessage               77FEA64A 5 Bytes  JMP 04E62E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] ole32.dll!CoGetClassObject               775056C5 5 Bytes  JMP 04E57B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!sendto                        71A52F51 5 Bytes  JMP 04E645E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!recvfrom                      71A52FF7 5 Bytes  JMP 04E64335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!closesocket                   71A53E2B 5 Bytes  JMP 04E62A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!connect                       71A54A07 5 Bytes  JMP 04E62574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!send                          71A54C27 5 Bytes  JMP 04E63069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSARecv                       71A54CB5 5 Bytes  JMP 04E660BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!recv                          71A5676F 5 Bytes  JMP 04E63A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSASend                       71A568FA 5 Bytes  JMP 04E635DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSARecvFrom                   71A5F66A 5 Bytes  JMP 04E663AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSASendTo                     71A60AAD 5 Bytes  JMP 04E64B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSAConnect                    71A60C81 5 Bytes  JMP 04E628EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WS2_32.dll!WSAGetOverlappedResult        71A60D1B 5 Bytes  JMP 04E63CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5644] WININET.dll!UnlockUrlCacheEntryFile      771C7D3C 5 Bytes  JMP 04E66AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] kernel32.dll!CreateProcessW              7C802336 5 Bytes  JMP 01A65001 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] kernel32.dll!GetQueuedCompletionStatus   7C80A7AD 5 Bytes  JMP 01A63FDC C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] Secur32.dll!EncryptMessage               77FEA5FB 5 Bytes  JMP 01A61489 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] Secur32.dll!DecryptMessage               77FEA64A 5 Bytes  JMP 01A62E14 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] ole32.dll!CoGetClassObject               775056C5 5 Bytes  JMP 01A57B16 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!sendto                        71A52F51 5 Bytes  JMP 01A645E3 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!recvfrom                      71A52FF7 5 Bytes  JMP 01A64335 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!closesocket                   71A53E2B 5 Bytes  JMP 01A62A61 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!connect                       71A54A07 5 Bytes  JMP 01A62574 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!send                          71A54C27 5 Bytes  JMP 01A63069 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSARecv                       71A54CB5 5 Bytes  JMP 01A660BB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!recv                          71A5676F 5 Bytes  JMP 01A63A52 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSASend                       71A568FA 5 Bytes  JMP 01A635DB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSARecvFrom                   71A5F66A 5 Bytes  JMP 01A663AF C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSASendTo                     71A60AAD 5 Bytes  JMP 01A64B72 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSAConnect                    71A60C81 5 Bytes  JMP 01A628EA C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WS2_32.dll!WSAGetOverlappedResult        71A60D1B 5 Bytes  JMP 01A63CEB C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)
.text                                                                     C:\Documents and Settings\Darek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[5956] WININET.dll!UnlockUrlCacheEntryFile      771C7D3C 5 Bytes  JMP 01A66AA5 C:\Program Files\RelevantKnowledge\rlls.dll (Relevant-Knowledge/TMRG,  Inc.)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT                                                                       \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_ULONG]                                                                                       [B7E93232] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!READ_PORT_UCHAR]                                                                                        [B7E92730] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       \WINDOWS\system32\DRIVERS\PCIIDEX.SYS[HAL.dll!WRITE_PORT_UCHAR]                                                                                       [B7E92F12] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                                                                    [B7E92730] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                                                                            [B7E92914] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                                                                   [B7E92856] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                                                                           [B7E930F0] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                                                                   [B7E92F12] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
IAT                                                                       \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                                                                    [B7EA6F1E] sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)

---- User IAT/EAT - GMER 1.0.15 ----

IAT                                                                       C:\WINDOWS\system32\services.exe[676] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]                                          003D0002
IAT                                                                       C:\WINDOWS\system32\services.exe[676] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]                                                003D0000

---- Devices - GMER 1.0.15 ----

Device                                                                    \FileSystem\Ntfs \Ntfs                                                                                                                                aswSP.SYS (avast! self protection module/ALWIL Software)
Device                                                                    \FileSystem\Ntfs \Ntfs                                                                                                                                8A88E1F8

AttachedDevice                                                            \FileSystem\Ntfs \Ntfs                                                                                                                                aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice                                                            \Driver\Tcpip \Device\Ip                                                                                                                              aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device                                                                    \Driver\usbuhci \Device\USBPDO-0                                                                                                                      8A7371F8
Device                                                                    \Driver\usbuhci \Device\USBPDO-1                                                                                                                      8A7371F8
Device                                                                    \Driver\usbuhci \Device\USBPDO-2                                                                                                                      8A7371F8
Device                                                                    \Driver\usbuhci \Device\USBPDO-3                                                                                                                      8A7371F8
Device                                                                    \Driver\usbehci \Device\USBPDO-4                                                                                                                      8A70A1F8

AttachedDevice                                                            \Driver\Tcpip \Device\Tcp                                                                                                                             aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device                                                                    \Driver\Cdrom \Device\CdRom0                                                                                                                          8A6FD430
Device                                                                    \Driver\atapi \Device\Ide\IdePort0                                                                                                                    [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\atapi \Device\Ide\IdePort1                                                                                                                    [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\atapi \Device\Ide\IdePort2                                                                                                                    [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-6                                                                                                           [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-e                                                                                                           [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\atapi \Device\Ide\IdePort3                                                                                                                    [B7E10B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device                                                                    \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                               8A64D430
Device                                                                    \Driver\usbstor \Device\00000085                                                                                                                      8A506430
Device                                                                    \Driver\usbstor \Device\00000085                                                                                                                      sfsync04.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device                                                                    \Driver\NetBT \Device\NetbiosSmb                                                                                                                      8A64D430
Device                                                                    \Driver\usbstor \Device\00000086                                                                                                                      8A506430
Device                                                                    \Driver\usbstor \Device\00000086                                                                                                                      sfsync04.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device                                                                    \Driver\usbstor \Device\00000087                                                                                                                      8A506430
Device                                                                    \Driver\usbstor \Device\00000087                                                                                                                      sfsync04.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device                                                                    \Driver\usbstor \Device\00000088                                                                                                                      8A506430
Device                                                                    \Driver\usbstor \Device\00000088                                                                                                                      sfsync04.sys (StarForce Protection Synchronization Driver/Protection Technology)

AttachedDevice                                                            \Driver\Tcpip \Device\Udp                                                                                                                             aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice                                                            \Driver\Tcpip \Device\RawIp                                                                                                                           aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device                                                                    \Driver\usbuhci \Device\USBFDO-0                                                                                                                      8A7371F8
Device                                                                    \Driver\usbuhci \Device\USBFDO-1                                                                                                                      8A7371F8
Device                                                                    \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                                                                     8A66C430
Device                                                                    \Driver\usbuhci \Device\USBFDO-2                                                                                                                      8A7371F8
Device                                                                    \FileSystem\MRxSmb \Device\LanmanRedirector                                                                                                           8A66C430
Device                                                                    \Driver\usbuhci \Device\USBFDO-3                                                                                                                      8A7371F8
Device                                                                    \Driver\usbehci \Device\USBFDO-4                                                                                                                      8A70A1F8
Device                                                                    \Driver\usbstor \Device\0000007f                                                                                                                      8A506430
Device                                                                    \Driver\usbstor \Device\0000007f                                                                                                                      sfsync04.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device                                                                    \FileSystem\Cdfs \Cdfs                                                                                                                                8A75F1F8

---- Registry - GMER 1.0.15 ----

Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                                      
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                   1
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                                0x68 0xDC 0x40 0xAA ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                      
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                   I:\Program Files\DAEMON Tools Lite\
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                   0x00 0x00 0x00 0x00 ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                   2
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                0xA3 0x91 0x26 0xEE ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                                      
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                   0
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                                0x90 0xAD 0x57 0x65 ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                                                   I:\Program Files\DAEMON Tools Lite\
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                                                             
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                                          0x20 0x01 0x00 0x00 ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                                                       0x88 0xCB 0xFB 0x04 ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                                                       
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                                                 0x1F 0xB6 0x47 0x1A ...
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41                                                       
Reg                                                                       HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                                                 0xF9 0x27 0x77 0x4A ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                                                  
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                                       1
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                                    0x68 0xDC 0x40 0xAA ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                  
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                       I:\Program Files\DAEMON Tools Lite\
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                       0x00 0x00 0x00 0x00 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                       2
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                    0x7B 0x03 0xC2 0x3A ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)                                         
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                                              0xA0 0x02 0x00 0x00 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                                           0x4C 0x5B 0x0E 0xE6 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)                                    
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                                                      0x21 0x7B 0x1D 0x16 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                                  
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                                       0
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                                    0x90 0xAD 0x57 0x65 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                                                       I:\Program Files\DAEMON Tools Lite\
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)                                         
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                                              0x20 0x01 0x00 0x00 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                                                           0x88 0xCB 0xFB 0x04 ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)                                   
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                                                     0x1F 0xB6 0x47 0x1A ...
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)                                   
Reg                                                                       HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh                                                     0xF9 0x27 0x77 0x4A ...
Reg                                                                       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8159C40D-6A66-91AC-9B3E-8412704E6939}                                       

---- Disk sectors - GMER 1.0.15 ----

Disk                                                                      \Device\Harddisk0\DR0                                                                                                                                 MBR read error
Disk                                                                      \Device\Harddisk0\DR0                                                                                                                                 MBR BIOS signature not found 0

---- Files - GMER 1.0.15 ----

File                                                                      C:\Documents and Settings\Darek\Ustawienia lokalne\Temporary Internet Files\Content.IE5\YZ07QRSZ\rule1[2].xml                                         0 bytes

---- EOF - GMER 1.0.15 ----
