Teil 2: Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by Christian at 2015-02-02 12:10:12
Running from C:\Users\Christian\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Reader XI (11.0.04) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.103.2020.206 - Alps Electric)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.3721 - CyberLink Corp.)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Host App Service (HKU\S-1-5-21-1715082490-1160310528-2700504390-1001\...\Pokki) (Version: 0.269.5.460 - Pokki)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.1.1000 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{26AA61D4-B04D-4E0D-8E20-94A8FF2EE64D}) (Version: 4.2.40.2439 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{105fa5c4-72e1-41f2-a82c-884d8aa4b381}) (Version: 16.6.0 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
NVIDIA Grafiktreiber 347.25 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.25 - NVIDIA Corporation)
Pokki Start Menu (HKU\S-1-5-21-1715082490-1160310528-2700504390-1001\...\Pokki_Start_Menu) (Version: 0.269.5.460 - Pokki)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21238 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Secure Eraser (HKLM-x32\...\Secure Eraser_is1) (Version: 4.2.0.1 - ASCOMP Software GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1715082490-1160310528-2700504390-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
01-02-2015 22:07:39 eBay Worldwide wird entfernt
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {03D6B953-5880-4BC8-8735-D9DEFFA0F88C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-12-31] (Microsoft Corporation)
Task: {13A0305C-47BB-4200-987C-2CD5929615E5} - System32\Tasks\Dolby Selector => C:\Program Files\Dolby Digital Plus\ddp.exe [2013-07-08] (Dolby Laboratories Inc.)
Task: {3F838EC8-10AE-4803-AD3A-84331CD3C35F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe
Task: {6F198B59-D743-48E5-8E75-66CBFB2A5816} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe
Task: {710ED092-BDC3-46A9-AD8C-2D63271D6627} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-01] (Google Inc.)
Task: {A88A6E15-DA8E-43AF-AB25-84C7C572E827} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe
Task: {F51DC9C7-CBA2-4BC2-899D-E2A904E4B2B9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-01] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2015-02-01 22:51 - 2015-01-10 00:29 - 00117392 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-08-12 18:06 - 2013-08-12 18:06 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2013-08-12 18:06 - 2013-08-12 18:06 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-08-12 18:06 - 2013-08-12 18:06 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
2014-06-10 20:27 - 2012-04-24 11:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2013-07-08 17:53 - 2013-07-08 17:53 - 00052096 _____ () C:\Program Files\Dolby Digital Plus\Dolby.DDP.Controls_Desktop.dll
2014-08-30 17:12 - 2014-08-30 17:12 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\kpcengine.2.3.dll
2014-06-10 19:40 - 2013-09-04 00:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-06-10 20:35 - 2014-01-03 13:13 - 00090368 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll
2015-02-01 22:04 - 2015-01-27 04:44 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libglesv2.dll
2015-02-01 22:04 - 2015-01-27 04:44 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\libegl.dll
2015-02-01 22:04 - 2015-01-27 04:44 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.94\pdf.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Christian\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1715082490-1160310528-2700504390-500 - Administrator - Disabled)
Christian (S-1-5-21-1715082490-1160310528-2700504390-1001 - Administrator - Enabled) => C:\Users\Christian
Gast (S-1-5-21-1715082490-1160310528-2700504390-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1715082490-1160310528-2700504390-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/02/2015 10:55:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (02/02/2015 08:08:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x17bc
Startzeit der fehlerhaften Anwendung: 0xfvz52uve.exe0
Pfad der fehlerhaften Anwendung: fvz52uve.exe1
Pfad des fehlerhaften Moduls: fvz52uve.exe2
Berichtskennung: fvz52uve.exe3
Vollständiger Name des fehlerhaften Pakets: fvz52uve.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: fvz52uve.exe5
Error: (02/02/2015 08:07:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x1008
Startzeit der fehlerhaften Anwendung: 0xfvz52uve.exe0
Pfad der fehlerhaften Anwendung: fvz52uve.exe1
Pfad des fehlerhaften Moduls: fvz52uve.exe2
Berichtskennung: fvz52uve.exe3
Vollständiger Name des fehlerhaften Pakets: fvz52uve.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: fvz52uve.exe5
Error: (02/02/2015 08:06:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x176c
Startzeit der fehlerhaften Anwendung: 0xfvz52uve.exe0
Pfad der fehlerhaften Anwendung: fvz52uve.exe1
Pfad des fehlerhaften Moduls: fvz52uve.exe2
Berichtskennung: fvz52uve.exe3
Vollständiger Name des fehlerhaften Pakets: fvz52uve.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: fvz52uve.exe5
Error: (02/02/2015 08:05:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: fvz52uve.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x174
Startzeit der fehlerhaften Anwendung: 0xfvz52uve.exe0
Pfad der fehlerhaften Anwendung: fvz52uve.exe1
Pfad des fehlerhaften Moduls: fvz52uve.exe2
Berichtskennung: fvz52uve.exe3
Vollständiger Name des fehlerhaften Pakets: fvz52uve.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: fvz52uve.exe5
Error: (02/02/2015 07:54:30 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Error: (02/02/2015 07:54:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
System errors:
=============
Error: (02/02/2015 10:59:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/02/2015 10:55:26 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}
Error: (02/02/2015 10:55:20 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}
Error: (02/02/2015 10:55:19 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (02/02/2015 10:55:19 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}
Error: (02/02/2015 10:55:19 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (02/02/2015 10:55:17 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}
Error: (02/02/2015 10:55:16 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (02/02/2015 10:55:16 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (02/02/2015 10:55:14 AM) (Source: DCOM) (EventID: 10010) (User: CHRIS)
Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474}
Microsoft Office Sessions:
=========================
Error: (02/02/2015 10:55:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147009280
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147009280
Error: (02/02/2015 10:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRIS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2147009280
Error: (02/02/2015 08:08:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fvz52uve.exe2.1.19357.052e7ea83fvz52uve.exe2.1.19357.052e7ea83c0000005000011aa17bc01d03eb70d373d60C:\Users\Christian\Downloads\fvz52uve.exeC:\Users\Christian\Downloads\fvz52uve.exe507ad1b0-aaaa-11e4-8262-c45444832e11
Error: (02/02/2015 08:07:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fvz52uve.exe2.1.19357.052e7ea83fvz52uve.exe2.1.19357.052e7ea83c0000005000011aa100801d03eb6ed403cdbC:\Users\Christian\Downloads\fvz52uve.exeC:\Users\Christian\Downloads\fvz52uve.exe2e5cd437-aaaa-11e4-8262-c45444832e11
Error: (02/02/2015 08:06:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fvz52uve.exe2.1.19357.052e7ea83fvz52uve.exe2.1.19357.052e7ea83c0000005000011aa176c01d03eb6b22996e8C:\Users\Christian\Downloads\fvz52uve.exeC:\Users\Christian\Downloads\fvz52uve.exef1c65951-aaa9-11e4-8262-c45444832e11
Error: (02/02/2015 08:05:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fvz52uve.exe2.1.19357.052e7ea83fvz52uve.exe2.1.19357.052e7ea83c0000005000011aa17401d03eb6a5801a82C:\Users\Christian\Downloads\fvz52uve.exeC:\Users\Christian\Downloads\fvz52uve.exee6f7b52e-aaa9-11e4-8262-c45444832e11
Error: (02/02/2015 07:54:30 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Christian\AppData\Local\Pokki\Engine\HostAppService.exe
Error: (02/02/2015 07:54:20 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Christian\AppData\Local\Pokki\Engine\HostAppService.exe
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 26%
Total physical RAM: 8072.27 MB
Available physical RAM: 5945.82 MB
Total Pagefile: 9992.27 MB
Available Pagefile: 7782.82 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:898.59 GB) (Free:855.68 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 6C3BD5B1)
Partition: GPT Partition Type.
==================== End Of Log ============================ GMER: Problem: Gmer startet mit Fehlermeldung, dass er auf Windows\system32\config\system nicht zugreifen kann, da ein anderes Programm da drauf zugreift. (Quick-)Scan funktioniert dann aber, endete aber mit der selben Fehlermeldung. Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-02 12:31:03
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002b ST1000LM014-1EJ164 rev.SM14 931,51GB
Running: 4lyrtrd3.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\fgldqpod.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\nvvsvc.exe[1020] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\nvvsvc.exe[1020] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\nvvsvc.exe[1020] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\nvvsvc.exe[1020] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\WLANExt.exe[1436] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\WLANExt.exe[1436] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\WLANExt.exe[1436] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\WLANExt.exe[1436] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffc65dd1f6a 4 bytes [DD, 65, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1800] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffc65dd1f82 4 bytes [DD, 65, FC, 7F]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[1952] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[1952] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[1952] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe[1952] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[1320] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[1320] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[1320] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[1320] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[1916] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[1916] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[1916] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[1916] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2692] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2692] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2692] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2692] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apoint.exe[4904] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apoint.exe[4904] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apoint.exe[4904] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apoint.exe[4904] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\ApMsgFwd.exe[5036] C:\Windows\system32\PSAPI.dll!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\ApMsgFwd.exe[5036] C:\Windows\system32\PSAPI.dll!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\ApMsgFwd.exe[5036] C:\Windows\system32\PSAPI.dll!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\ApMsgFwd.exe[5036] C:\Windows\system32\PSAPI.dll!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apntex.exe[5104] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffc724d169a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apntex.exe[5104] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffc724d16a2 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apntex.exe[5104] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffc724d181a 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files\Apoint2K\Apntex.exe[5104] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffc724d1832 4 bytes [4D, 72, FC, 7F]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffc729a2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 436 00007ffc729a2ef0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffc729a3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffc729a4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 491 00007ffc729a4bbb 8 bytes {JMP 0xfffffffffffffff3}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffc729a4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffc729a511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 676 00007ffc729a52a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc729a6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 824 00007ffc729aabf4 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 987 00007ffc729aac97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffc729ab218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffc729ab88c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffc729abc38 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc729abe94 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseWait + 168 00007ffc729ac408 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDeregisterWaitEx + 683 00007ffc729ac74f 8 bytes {JMP 0xffffffffffffffd6}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc729acdfb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlGetLocaleFileMappingAddress + 151 00007ffc729acfaf 8 bytes {JMP 0xffffffffffffffd9}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlpInitializeLangRegistryInfo + 36 00007ffc729acfdc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc729ada20 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlpMuiRegLoadRegistryInfo + 224 00007ffc729ae120 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlGetActiveActivationContext + 751 00007ffc729afcab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlIsCriticalSectionLockedByThread + 296 00007ffc729b0694 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!LdrShutdownProcess + 772 00007ffc729b17cc 8 bytes {JMP 0xffffffffffffffc7}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextUnsafeFast + 403 00007ffc729b3267 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc729b3aa8 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc729b3b30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlInitAnsiString + 324 00007ffc729b5734 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeStringToString + 143 00007ffc729b57cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 32 00007ffc729b6c18 8 bytes [70, 6C, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 67 00007ffc729b6c3b 8 bytes [60, 6C, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 367 00007ffc729b813b 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 971 00007ffc729b8397 8 bytes [40, 6C, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 159 00007ffc729b843f 8 bytes [30, 6C, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToNtPathName_U_WithStatus + 872 00007ffc729b8824 8 bytes [20, 6C, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!RtlAnsiCharToUnicodeChar + 115 00007ffc729bd3b3 8 bytes {JMP 0xffffffffffffffc5}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc72a21740 8 bytes {JMP QWORD [RIP-0x693af]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc72a218c0 8 bytes {JMP QWORD [RIP-0x69487]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc72a218f0 8 bytes {JMP QWORD [RIP-0x6acde]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc72a21a10 8 bytes {JMP QWORD [RIP-0x698db]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc72a21ac0 8 bytes {JMP QWORD [RIP-0x6ae8b]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc72a22180 8 bytes {JMP QWORD [RIP-0x63432]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc72a22480 8 bytes {JMP QWORD [RIP-0x650d3]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc72a22d00 8 bytes {JMP QWORD [RIP-0x6a4e2]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 389 0000000077471385 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077471512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077471551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077471577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000774717e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077471834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077471841 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 17 0000000077471851 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4540] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077472c1c 8 bytes [DC, 6A, 15, 7F, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffc729a2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 436 00007ffc729a2ef0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffc729a3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffc729a4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 491 00007ffc729a4bbb 8 bytes {JMP 0xfffffffffffffff3}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffc729a4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffc729a511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 676 00007ffc729a52a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc729a6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 824 00007ffc729aabf4 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 987 00007ffc729aac97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffc729ab218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffc729ab88c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffc729abc38 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc729abe94 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseWait + 168 00007ffc729ac408 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDeregisterWaitEx + 683 00007ffc729ac74f 8 bytes {JMP 0xffffffffffffffd6}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc729acdfb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlGetLocaleFileMappingAddress + 151 00007ffc729acfaf 8 bytes {JMP 0xffffffffffffffd9}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlpInitializeLangRegistryInfo + 36 00007ffc729acfdc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc729ada20 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlpMuiRegLoadRegistryInfo + 224 00007ffc729ae120 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlGetActiveActivationContext + 751 00007ffc729afcab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlIsCriticalSectionLockedByThread + 296 00007ffc729b0694 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!LdrShutdownProcess + 772 00007ffc729b17cc 8 bytes {JMP 0xffffffffffffffc7}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextUnsafeFast + 403 00007ffc729b3267 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc729b3aa8 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc729b3b30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlInitAnsiString + 324 00007ffc729b5734 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeStringToString + 143 00007ffc729b57cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 32 00007ffc729b6c18 8 bytes [70, 6C, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 67 00007ffc729b6c3b 8 bytes [60, 6C, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 367 00007ffc729b813b 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 971 00007ffc729b8397 8 bytes [40, 6C, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 159 00007ffc729b843f 8 bytes [30, 6C, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToNtPathName_U_WithStatus + 872 00007ffc729b8824 8 bytes [20, 6C, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!RtlAnsiCharToUnicodeChar + 115 00007ffc729bd3b3 8 bytes {JMP 0xffffffffffffffc5}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc72a21740 8 bytes {JMP QWORD [RIP-0x693af]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc72a218c0 8 bytes {JMP QWORD [RIP-0x69487]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc72a218f0 8 bytes {JMP QWORD [RIP-0x6acde]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc72a21a10 8 bytes {JMP QWORD [RIP-0x698db]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc72a21ac0 8 bytes {JMP QWORD [RIP-0x6ae8b]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc72a22180 8 bytes {JMP QWORD [RIP-0x63432]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc72a22480 8 bytes {JMP QWORD [RIP-0x650d3]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc72a22d00 8 bytes {JMP QWORD [RIP-0x6a4e2]}
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 389 0000000077471385 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077471512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077471551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077471577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000774717e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077471834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077471841 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 17 0000000077471851 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe[4660] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077472c1c 8 bytes [DC, 6A, 67, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffc729a2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 436 00007ffc729a2ef0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffc729a3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffc729a4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 491 00007ffc729a4bbb 8 bytes {JMP 0xfffffffffffffff3}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffc729a4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffc729a511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 676 00007ffc729a52a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc729a6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 824 00007ffc729aabf4 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 987 00007ffc729aac97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffc729ab218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffc729ab88c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffc729abc38 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc729abe94 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseWait + 168 00007ffc729ac408 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDeregisterWaitEx + 683 00007ffc729ac74f 8 bytes {JMP 0xffffffffffffffd6}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc729acdfb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlGetLocaleFileMappingAddress + 151 00007ffc729acfaf 8 bytes {JMP 0xffffffffffffffd9}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlpInitializeLangRegistryInfo + 36 00007ffc729acfdc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc729ada20 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlpMuiRegLoadRegistryInfo + 224 00007ffc729ae120 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlGetActiveActivationContext + 751 00007ffc729afcab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlIsCriticalSectionLockedByThread + 296 00007ffc729b0694 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!LdrShutdownProcess + 772 00007ffc729b17cc 8 bytes {JMP 0xffffffffffffffc7}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextUnsafeFast + 403 00007ffc729b3267 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc729b3aa8 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc729b3b30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlInitAnsiString + 324 00007ffc729b5734 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeStringToString + 143 00007ffc729b57cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 32 00007ffc729b6c18 8 bytes [70, 6C, CE, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 67 00007ffc729b6c3b 8 bytes [60, 6C, CE, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 367 00007ffc729b813b 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 971 00007ffc729b8397 8 bytes [40, 6C, CE, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 159 00007ffc729b843f 8 bytes [30, 6C, CE, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToNtPathName_U_WithStatus + 872 00007ffc729b8824 8 bytes [20, 6C, CE, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!RtlAnsiCharToUnicodeChar + 115 00007ffc729bd3b3 8 bytes {JMP 0xffffffffffffffc5}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc72a21740 8 bytes {JMP QWORD [RIP-0x693af]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc72a218c0 8 bytes {JMP QWORD [RIP-0x69487]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc72a218f0 8 bytes {JMP QWORD [RIP-0x6acde]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc72a21a10 8 bytes {JMP QWORD [RIP-0x698db]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc72a21ac0 8 bytes {JMP QWORD [RIP-0x6ae8b]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc72a22180 8 bytes {JMP QWORD [RIP-0x63432]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc72a22480 8 bytes {JMP QWORD [RIP-0x650d3]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc72a22d00 8 bytes {JMP QWORD [RIP-0x6a4e2]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 389 0000000077471385 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077471512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077471551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077471577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000774717e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077471834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077471841 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 17 0000000077471851 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5100] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077472c1c 8 bytes [DC, 6A, CE, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffc729a2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 436 00007ffc729a2ef0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffc729a3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffc729a4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 491 00007ffc729a4bbb 8 bytes {JMP 0xfffffffffffffff3}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffc729a4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffc729a511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 676 00007ffc729a52a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc729a6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 824 00007ffc729aabf4 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 987 00007ffc729aac97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffc729ab218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffc729ab88c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffc729abc38 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc729abe94 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseWait + 168 00007ffc729ac408 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDeregisterWaitEx + 683 00007ffc729ac74f 8 bytes {JMP 0xffffffffffffffd6}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc729acdfb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlGetLocaleFileMappingAddress + 151 00007ffc729acfaf 8 bytes {JMP 0xffffffffffffffd9}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlpInitializeLangRegistryInfo + 36 00007ffc729acfdc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc729ada20 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlpMuiRegLoadRegistryInfo + 224 00007ffc729ae120 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlGetActiveActivationContext + 751 00007ffc729afcab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlIsCriticalSectionLockedByThread + 296 00007ffc729b0694 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!LdrShutdownProcess + 772 00007ffc729b17cc 8 bytes {JMP 0xffffffffffffffc7}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextUnsafeFast + 403 00007ffc729b3267 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc729b3aa8 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc729b3b30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlInitAnsiString + 324 00007ffc729b5734 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeStringToString + 143 00007ffc729b57cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 32 00007ffc729b6c18 8 bytes [70, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToRelativeNtPathName_U_WithStatus + 67 00007ffc729b6c3b 8 bytes [60, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 367 00007ffc729b813b 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlHashUnicodeString + 971 00007ffc729b8397 8 bytes [40, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 159 00007ffc729b843f 8 bytes [30, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlDosPathNameToNtPathName_U_WithStatus + 872 00007ffc729b8824 8 bytes [20, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!RtlAnsiCharToUnicodeChar + 115 00007ffc729bd3b3 8 bytes {JMP 0xffffffffffffffc5}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc72a21740 8 bytes {JMP QWORD [RIP-0x693af]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc72a218c0 8 bytes {JMP QWORD [RIP-0x69487]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc72a218f0 8 bytes {JMP QWORD [RIP-0x6acde]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc72a21a10 8 bytes {JMP QWORD [RIP-0x698db]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc72a21ac0 8 bytes {JMP QWORD [RIP-0x6ae8b]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc72a22180 8 bytes {JMP QWORD [RIP-0x63432]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc72a22480 8 bytes {JMP QWORD [RIP-0x650d3]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc72a22d00 8 bytes {JMP QWORD [RIP-0x6a4e2]}
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 389 0000000077471385 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077471512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077471551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077471577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000774717e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077471834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077471841 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 17 0000000077471851 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Christian\Desktop\4lyrtrd3.exe[1428] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077472c1c 8 bytes [DC, 6A, F8, 7F, 00, 00, 00, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [688:712] fffff960008b7b90
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1756] 0000000000c56983
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3068] 0000000074837c20
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2104] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1280] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1312] 00000000748668d7
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2532] 0000000073436d20
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2776] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2724] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2816] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2936] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2932] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2928] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2924] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2916] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2980] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:584] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2988] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2992] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:672] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2496] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2052] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2552] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2528] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2764] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2548] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2212] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2780] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:556] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2912] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2392] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3076] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3080] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3084] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3088] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3092] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3120] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3128] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3132] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3144] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3148] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3152] 0000000073541bf5
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3156] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3160] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3188] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3192] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3196] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3200] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3204] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3208] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3212] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3216] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3228] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3232] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3236] 00000000721cbf09
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3240] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3244] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3256] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3260] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3264] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3268] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3272] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3276] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3280] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3284] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3288] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3292] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3296] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3300] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3304] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3308] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3312] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3316] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3320] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3328] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3332] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3344] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3348] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3352] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3356] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3360] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3488] 00000000708f69c0
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3492] 00000000708f69c0
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3496] 0000000070950060
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3500] 00000000708c9fc8
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3528] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3584] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3592] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:824] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2564] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1528] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:896] 0000000073041120
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:144] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2176] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5000] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:6120] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4216] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1180] 0000000061d725b8
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3404] 0000000061d725b8
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2704] 0000000061d725b8
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5396] 0000000061d725b8
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2252] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2976] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:560] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4384] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4372] 0000000074a0a4c5
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2296] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3884] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2644] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5004] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4244] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5464] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5028] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5664] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1200] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4212] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4680] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4076] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5572] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4676] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3856] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:752] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2972] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3704] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3656] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:4416] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:1832] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:6128] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:2720] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5624] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:3544] 0000000074c5c59c
Thread C:\Windows\SYSTEM32\ntdll.dll [1752:5164] 0000000076fd62d0
Thread C:\Windows\System32\SettingSyncHost.exe [5348:5368] 00007ffc56e56da0
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Ich hoffe das reicht für den Anfang.
Liebe Grüße
Christian |