GMER Teil 2: Code:
.text C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe[6604] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe[6604] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe[6604] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 97, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, D9, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, D9, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, D9, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, D9, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[5576] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, D9, 7F, 00, 00, 00, ...]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff8835e1f6a 4 bytes [5E, 83, F8, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff8835e1f82 4 bytes [5E, 83, F8, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8852d169a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8852d16a2 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8852d181a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[5012] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8852d1832 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3912] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8852d169a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3912] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8852d16a2 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3912] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8852d181a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3912] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8852d1832 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, 2F, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, 2F, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, 2F, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, 2F, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1424] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 2F, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, 3B, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, 3B, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, 3B, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, 3B, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7692] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 3B, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, 22, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, 22, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, 22, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, 22, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6888] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 22, FE, 00, 00, 00, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Rene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe[7308] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7484] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff8852d169a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7484] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff8852d16a2 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7484] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff8852d181a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[7484] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff8852d1832 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, 1E, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, 1E, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, 1E, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, 1E, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5036] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 1E, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[7496] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff8852d169a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[7496] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff8852d16a2 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[7496] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff8852d181a 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[7496] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff8852d1832 4 bytes [2D, 85, F8, 7F]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ff887996658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ff887996668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ff887996867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ff887996887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ff887996bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ff887996c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ff887999188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ff8879991a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ff8879992f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ff88799931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ff88799950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ff887999577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ff8879995e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ff88799986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ff887999a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ff88799a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ff88799a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ff88799aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ff88799d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ff88799d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ff88799d75c 8 bytes [F0, 69, 53, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ff88799e56b 8 bytes [D0, 69, 53, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ff88799e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ff88799e6c3 8 bytes [B0, 69, 53, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ff88799e847 8 bytes [A0, 69, 53, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff887a1ac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff887a1add0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff887a1ae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff887a1af20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff887a1afd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff887a1b690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff887a1b990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff887a1c210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b8137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b81512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b81551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b81577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b81784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b817c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b817e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b81834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b81841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b81a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b82ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b82c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[620] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b82c43 8 bytes [7C, 68, 53, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ff88799293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ff887992959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ff8879929c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ff887992aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ff887992bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ff887993018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ff8879933bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ff887993404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ff8879935bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ff887993fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ff887994933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ff887994bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ff887994c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ff88799543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ff8879956b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ff887995a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ff887995f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ff887995fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ff8879960df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ff887996113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6572] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ff88799635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... |