netzstrolch | 23.03.2015 18:01 | GMER Teil 1: Code:
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4092] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076e31398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076e3143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076e31594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076e3191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076e31bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076e31d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076e31edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076e31fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076e327b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076e327d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076e3282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076e32898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076e32d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076e32d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076e3323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076e333c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076e33a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076e33ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076e33b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076e34190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076e34241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076e342b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076e343f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076e34434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076e345d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076e346d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076e34a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076e34b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076e34c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076e34d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076e34ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076e34ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076e350f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2764] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076e31398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076e3143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076e31594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076e3191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076e31bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076e31d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076e31edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076e31fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076e327b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076e327d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076e3282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076e32898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076e32d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 GMER Teil 2: Code:
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076e3323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076e333c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076e33a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076e33ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076e33b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076e34190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076e34241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076e342b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076e343f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076e34434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076e345d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076e346d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076e34a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076e34b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076e34c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076e34d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076e34ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076e34ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076e350f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3848] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076e31398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076e3143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076e31594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076e3191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076e31bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076e31d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076e31edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076e31fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076e327b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076e327d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076e3282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076e32898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076e32d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076e32d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076e3323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076e333c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076e33a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076e33ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076e33b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076e34190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076e34241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076e342b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076e343f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076e34434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076e345d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076e346d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076e34a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076e34b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076e34c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076e34d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076e34ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076e34ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076e350f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[3256] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076e31398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076e3143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076e31594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076e3191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076e31bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076e31d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076e31edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076e31fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076e327b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076e327d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076e3282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076e32898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076e32d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076e32d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076e3323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076e333c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076e33a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076e33ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076e33b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076e34190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076e34241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076e342b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076e343f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076e34434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076e345d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076e346d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076e34a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076e34b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076e34c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076e34d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076e34ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076e34ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076e350f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5572] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076e31398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076e3143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076e31594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076e3191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076e31bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076e31d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076e31edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076e31fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076e327b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076e327d2 8 bytes {JMP 0x10}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076e3282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076e32898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076e32d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076e32d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076e3323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076e333c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076e33a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076e33ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076e33b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076e34190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076e34241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076e342b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076e343f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076e34434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076e345d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076e346d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076e34a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076e34b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076e34c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076e34d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076e34ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076e34ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076e350f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076e352f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076e353f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076e355e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076e364d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076e3668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076e3687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076e368bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076e368d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076e3692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076e37166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076e37dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076e37e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076e81380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076e81500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076e81530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076e81650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076e81700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076e81d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076e81f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076e827e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000748c13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000748c146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000748c16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000748c19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000748c19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\Gmer-19357.exe[4296] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000748c1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [2968:3596] 000007fef63c9688
---- Processes - GMER 2.1 ----
Library C:\Program Files (x86)\RaseIdymusculturate\Qt5Core.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-31 12:39:18) 0000000066740000
Library C:\Program Files (x86)\RaseIdymusculturate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792](2014-10-31 12:39:18) 000000006e940000
Library C:\Program Files (x86)\RaseIdymusculturate\libwinpthread-1.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792] (POSIX WinThreads for Windows/MingW-W64 Project. All rights reserved.)(2014-10-31 12:39:18) 0000000064940000
Library C:\Program Files (x86)\RaseIdymusculturate\libstdc++-6.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792](2014-10-31 12:39:18) 000000006fc40000
Library C:\Program Files (x86)\RaseIdymusculturate\Qt5Network.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-31 12:39:18) 000000006d200000
Library C:\Program Files (x86)\RaseIdymusculturate\ssleay32.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2014-10-31 12:39:18) 000000006e400000
Library C:\Program Files (x86)\RaseIdymusculturate\LIBEAY32.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturate.exe [1792] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2014-10-31 12:39:18) 0000000063000000
Library C:\Program Files (x86)\RaseIdymusculturate\Qt5Core.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturateHelper.exe [2588] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-31 12:39:18) 0000000066740000
Library C:\Program Files (x86)\RaseIdymusculturate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturateHelper.exe [2588](2014-10-31 12:39:18) 000000006e940000
Library C:\Program Files (x86)\RaseIdymusculturate\libwinpthread-1.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturateHelper.exe [2588] (POSIX WinThreads for Windows/MingW-W64 Project. All rights reserved.)(2014-10-31 12:39:18) 0000000064940000
Library C:\Program Files (x86)\RaseIdymusculturate\libstdc++-6.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturateHelper.exe [2588](2014-10-31 12:39:18) 000000006fc40000
Library C:\Program Files (x86)\RaseIdymusculturate\Qt5Network.dll (*** suspicious ***) @ C:\Program Files (x86)\RaseIdymusculturate\RaseIdymusculturateHelper.exe [2588] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-10-31 12:39:18) 000000006d200000
---- EOF - GMER 2.1 ---- |