Kaprisonne | 24.05.2015 00:48 | Gmer.txt: (Teil 2) Code:
* 2
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 000000007724306b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000772431f8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 000000007724388e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000772438e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000772439b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077243f50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077244001 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077244075 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000772441b6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000772441f4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000077244461 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 000000007724464c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077244713 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077244807 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077244926 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077244a50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077244aa3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077244ca5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077244ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077244fa7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000077245193 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077245f46 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000077246016 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 000000007724610e 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000772462fc 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 000000007724633d 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077246354 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000772463ac 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077246b76 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007728dc80 8 bytes {JMP QWORD [RIP-0x47949]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007728de00 8 bytes {JMP QWORD [RIP-0x47ab2]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007728de30 8 bytes {JMP QWORD [RIP-0x47e20]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007728df50 8 bytes {JMP QWORD [RIP-0x47c5a]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007728e000 8 bytes {JMP QWORD [RIP-0x47ef8]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007728e630 8 bytes {JMP QWORD [RIP-0x47102]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007728e880 8 bytes {JMP QWORD [RIP-0x47d10]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007728f0e0 8 bytes {JMP QWORD [RIP-0x48d3a]}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074cd13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074cd146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074cd16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074cd19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074cd19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074cd1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076351401 2 bytes JMP 7673b21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076351419 2 bytes JMP 7673b346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076351431 2 bytes JMP 767b8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007635144a 2 bytes CALL 7671489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000763514dd 2 bytes JMP 767b8822 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000763514f5 2 bytes JMP 767b89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007635150d 2 bytes JMP 767b8718 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076351525 2 bytes JMP 767b8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007635153d 2 bytes JMP 7672fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076351555 2 bytes JMP 767368ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007635156d 2 bytes JMP 767b8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076351585 2 bytes JMP 767b8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007635159d 2 bytes JMP 767b86dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000763515b5 2 bytes JMP 7672fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000763515cd 2 bytes JMP 7673b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000763516b2 2 bytes JMP 767b8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Local\Akamai\netsession_win.exe[4036] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000763516bd 2 bytes JMP 767b8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000772413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077241544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000772418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077241ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077241d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077241e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077241f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077242238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 531 0000000077242683 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000772426a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000772426c2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007724271f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077242788 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 4
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077242b4b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077242b97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 000000007724306b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000772431f8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 000000007724388e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000772438e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000772439b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077243f50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077244001 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077244075 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000772441b6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000772441f4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000077244461 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 000000007724464c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077244713 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077244807 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077244926 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077244a50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077244aa3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077244ca5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077244ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077244fa7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000077245193 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077245f46 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000077246016 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 000000007724610e 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000772462fc 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 000000007724633d 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077246354 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000772463ac 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077246b76 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007728dc80 8 bytes {JMP QWORD [RIP-0x47949]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007728de00 8 bytes {JMP QWORD [RIP-0x47ab2]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007728de30 8 bytes {JMP QWORD [RIP-0x47e20]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007728df50 8 bytes {JMP QWORD [RIP-0x47c5a]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007728e000 8 bytes {JMP QWORD [RIP-0x47ef8]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007728e630 8 bytes {JMP QWORD [RIP-0x47102]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007728e880 8 bytes {JMP QWORD [RIP-0x47d10]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007728f0e0 8 bytes {JMP QWORD [RIP-0x48d3a]}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074cd13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074cd146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074cd16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074cd19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074cd19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD (DDCCI)\LcdctrlDdcci.exe[3140] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074cd1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000772413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077241544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000772418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077241ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077241d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077241e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077241f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077242238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 531 0000000077242683 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000772426a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000772426c2 8 bytes {JMP 0x10}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007724271f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077242788 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 4
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077242b4b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077242b97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 000000007724306b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000772431f8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 000000007724388e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000772438e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000772439b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077243f50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077244001 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077244075 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000772441b6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000772441f4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000077244461 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 000000007724464c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077244713 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077244807 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077244926 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077244a50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077244aa3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077244ca5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077244ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077244fa7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000077245193 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077245f46 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000077246016 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 000000007724610e 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000772462fc 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 000000007724633d 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077246354 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000772463ac 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077246b76 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007728dc80 8 bytes {JMP QWORD [RIP-0x47949]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007728de00 8 bytes {JMP QWORD [RIP-0x47ab2]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007728de30 8 bytes {JMP QWORD [RIP-0x47e20]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007728df50 8 bytes {JMP QWORD [RIP-0x47c5a]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007728e000 8 bytes {JMP QWORD [RIP-0x47ef8]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007728e630 8 bytes {JMP QWORD [RIP-0x47102]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007728e880 8 bytes {JMP QWORD [RIP-0x47d10]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007728f0e0 8 bytes {JMP QWORD [RIP-0x48d3a]}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074cd13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074cd146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074cd16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074cd19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074cd19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074cd1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000076351401 2 bytes JMP 7673b21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000076351419 2 bytes JMP 7673b346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000076351431 2 bytes JMP 767b8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 42 000000007635144a 2 bytes CALL 7671489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 00000000763514dd 2 bytes JMP 767b8822 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 00000000763514f5 2 bytes JMP 767b89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 000000007635150d 2 bytes JMP 767b8718 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000076351525 2 bytes JMP 767b8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 000000007635153d 2 bytes JMP 7672fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000076351555 2 bytes JMP 767368ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 000000007635156d 2 bytes JMP 767b8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000076351585 2 bytes JMP 767b8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 000000007635159d 2 bytes JMP 767b86dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 00000000763515b5 2 bytes JMP 7672fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 00000000763515cd 2 bytes JMP 7673b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 00000000763516b2 2 bytes JMP 767b8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2204] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 31 00000000763516bd 2 bytes JMP 767b8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000772413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077241544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000772418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077241ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077241d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077241e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077241f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077242238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 531 0000000077242683 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000772426a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000772426c2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007724271f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077242788 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 4
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077242b4b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077242b97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 000000007724306b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000772431f8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 000000007724388e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000772438e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000772439b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077243f50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077244001 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077244075 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000772441b6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000772441f4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000077244461 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 000000007724464c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077244713 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077244807 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077244926 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077244a50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077244aa3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077244ca5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077244ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077244fa7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000077245193 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077245f46 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000077246016 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 000000007724610e 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000772462fc 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 000000007724633d 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077246354 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000772463ac 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077246b76 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007728dc80 8 bytes {JMP QWORD [RIP-0x47949]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007728de00 8 bytes {JMP QWORD [RIP-0x47ab2]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007728de30 8 bytes {JMP QWORD [RIP-0x47e20]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007728df50 8 bytes {JMP QWORD [RIP-0x47c5a]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007728e000 8 bytes {JMP QWORD [RIP-0x47ef8]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007728e630 8 bytes {JMP QWORD [RIP-0x47102]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007728e880 8 bytes {JMP QWORD [RIP-0x47d10]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007728f0e0 8 bytes {JMP QWORD [RIP-0x48d3a]}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074cd13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074cd146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074cd16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074cd19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074cd19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4172] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074cd1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000772413ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077241544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000772418ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077241ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077241d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077241e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077241f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077242238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 531 0000000077242683 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000772426a0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000772426c2 8 bytes {JMP 0x10}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007724271f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077242788 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 4
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077242b4b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077242b97 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 000000007724306b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000772431f8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 000000007724388e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000772438e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000772439b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077243f50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077244001 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077244075 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000772441b6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000772441f4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000077244461 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 000000007724464c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077244713 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077244807 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077244926 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077244a50 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077244aa3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077244ca5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077244ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077244fa7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000077245193 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077245f46 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000077246016 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 000000007724610e 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000772462fc 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 000000007724633d 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077246354 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000772463ac 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077246b76 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007728dc80 8 bytes {JMP QWORD [RIP-0x47949]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007728de00 8 bytes {JMP QWORD [RIP-0x47ab2]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007728de30 8 bytes {JMP QWORD [RIP-0x47e20]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007728df50 8 bytes {JMP QWORD [RIP-0x47c5a]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007728e000 8 bytes {JMP QWORD [RIP-0x47ef8]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007728e630 8 bytes {JMP QWORD [RIP-0x47102]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007728e880 8 bytes {JMP QWORD [RIP-0x47d10]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007728f0e0 8 bytes {JMP QWORD [RIP-0x48d3a]}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074cd13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074cd146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074cd16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074cd19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074cd19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Jannik\Desktop\Gmer-19357.exe[4340] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074cd1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [3428:6484] 000007feef729688
---- Processes - GMER 2.1 ----
Library c:\users\jannik\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqmtvai.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204](2015-05-23 11:34:36) 0000000003e60000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Core.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:24) 0000000069b30000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\icuin52.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (ICU I18N DLL/The ICU Project)(2015-03-04 21:45:30) 000000004a900000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\icuuc52.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (ICU Common DLL/The ICU Project)(2015-03-04 21:45:30) 0000000005e10000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\icudt52.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (ICU Data DLL/The ICU Project)(2015-03-04 21:45:30) 000000004ad00000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Widgets.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:28) 00000000626e0000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Gui.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 00000000623f0000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\libGLESv2.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204](2015-03-04 21:45:30) 0000000069430000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Network.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 0000000062210000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5WebKit.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 0000000060330000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Quick.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 0000000060110000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Qml.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 000000005feb0000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5Sql.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 00000000696e0000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\libEGL.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204](2015-03-04 21:45:30) 0000000069a70000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5WebKitWidgets.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:28) 0000000069010000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5OpenGL.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 0000000068fd0000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Qt5PrintSupport.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2015-03-04 21:45:26) 0000000068f80000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204](2015-03-04 21:45:30) 0000000068c60000
Library C:\Users\Jannik\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll (*** suspicious ***) @ C:\Users\Jannik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2204](2015-03-04 21:45:30) 0000000068c20000
---- EOF - GMER 2.1 ---- Vielleicht findet ihr ja was.
Grüße und :dankeschoen: ,
Kaprisonne
Edit:
Es liegt übrigens nicht am Spiel. Auch wenn ich nur am rumsurfen bin kommt der ladene Mauszeiger ab und zu. |