gorbiWTF | 26.08.2015 07:32 | Hier Teil 2: Addition.txt: Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:25-08-2015 02
durchgeführt von Karner (2015-08-26 08:04:04)
Gestartet von C:\Users\Karner\Desktop\2
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-1967446285-4052042257-1953947229-500 - Administrator - Disabled)
Gast (S-1-5-21-1967446285-4052042257-1953947229-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1967446285-4052042257-1953947229-1003 - Limited - Enabled)
Karner (S-1-5-21-1967446285-4052042257-1953947229-1001 - Administrator - Enabled) => C:\Users\Karner
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
A1 Dashboard (HKLM-x32\...\A1 Dashboard) (Version: 1.16.1.0 - A1 Telekom Austria AG)
A1 Dashboard (x32 Version: 1.16.1.0 - A1 Telekom Austria AG) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.6.0.6090 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{7DB34D93-22BA-BE2B-6DB9-56D84E98C1DB}) (Version: 3.0.851.0 - Advanced Micro Devices, Inc.)
ArcSoft TotalMedia (HKLM-x32\...\ArcSoft TotalMedia) (Version: 2.0.39.12 - ArcSoft)
ArcSoft TotalMedia (x32 Version: 1.0.48.25 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.30 - ArcSoft)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CardRecoveryPro 2.6.5 (HKLM-x32\...\{D9E1CADA-D103-47AE-B3F8-0C0CD0E5856E}_is1) (Version: 2.6.5 - LionSea Software co., ltd)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Device Access Manager for HP ProtectTools (HKLM\...\{55B52830-024A-443E-AF61-61E1E71AFA1B}) (Version: 6.1.0.1 - Hewlett-Packard Company)
Drive Encryption For HP ProtectTools (HKLM\...\{8A0041CD-277C-4C1F-BFE4-7AC508B20B4C}) (Version: 6.0.100.35469 - Hewlett-Packard Company)
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Face Recognition for HP ProtectTools (HKLM\...\{D3A775F2-2674-4452-8D80-1FC1446052EE}) (Version: 6.00.4407 - Hewlett-Packard Company)
File Sanitizer For HP ProtectTools (HKLM-x32\...\{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}) (Version: 6.0.0.8 - Hewlett-Packard Company)
Free YouTube Download version 3.2.49.1022 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.49.1022 - DVDVideoSoft Ltd.)
Free YouTube to iPhone Converter version 2.12.9.725 (HKLM-x32\...\Free YouTube to iPhone Converter_is1) (Version: 2.12.9.725 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.43.806 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.43.806 - DVDVideoSoft Ltd.)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
GeoGebra 4.2 (HKLM-x32\...\GeoGebra 4.2) (Version: 4.2.57.0 - International GeoGebra Institute)
Google Chrome (HKU\S-1-5-21-1967446285-4052042257-1953947229-1001\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6710.2136 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ACHTUNG
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP ESU for Microsoft Windows 7 (HKLM-x32\...\{840021F2-FFC0-467A-BF85-29B8B7803717}) (Version: 2.0.8.1 - Hewlett-Packard Company)
HP ProtectTools Security Manager (HKLM\...\HPProtectTools) (Version: 6.08.1017 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{3F437675-F102-4866-BDE1-FFFC7B45EC0B}) (Version: 3.1.2.10229 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{FE465061-894A-4023-8580-56FCDD4F23F9}) (Version: 3.4.4.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{D2462056-BA75-4B2C-8267-DFEA2B6AC4AE}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{531000B3-DBEE-4115-BBF3-DA48B67C053F}) (Version: 8.2.1.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP System Default Settings (HKLM-x32\...\{EE5F1911-EA95-4F1A-AF97-495972F5032D}) (Version: 2.4.3.1 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 2.00 - Hewlett-Packard Company)
HP Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50058.0 - Sonix)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6428.0 - IDT)
Intel(R) Identity Protection Technology 1.0.71.0 (HKLM-x32\...\{2C43790E-8470-1027-82D3-DF319F3C410F}) (Version: 1.0.71.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
InterActual Player (HKLM-x32\...\InterActual Player) (Version: - )
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.72.4 - JMicron Technology Corp.)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}) (Version: 15.0.0.463 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.0.463 - Kaspersky Lab) Hidden
L&H TTS3000 Deutsch (HKLM-x32\...\LHTTSGED) (Version: - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.64 - PDF Complete, Inc)
PNotes 9.0.107 (HKLM-x32\...\{949D34E5-F53F-4830-9A50-1E2C39109043}_is1) (Version: 9.0.107 - Andrey Gruber)
Privacy Manager for HP ProtectTools (HKLM\...\{ACA53F68-B003-4D0E-9C3D-0C4EE09D08A8}) (Version: 6.00.831 - Hewlett-Packard Company)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
Realtek Motorola BC8 Bluetooth 3.0+HS Adapter (HKLM\...\1DF1F719-D43A-46E8-950F-65A8D96C678A.MBT_is1) (Version: 3.0.82.298 - Motorola Solutions, Inc.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.11.0706 - REALTEK Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Stellar Phoenix Photo Recovery (HKLM-x32\...\Stellar Phoenix Photo Recovery_is1) (Version: 6.0.0.1 - Stellar Information Technology Pvt Ltd.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.8.9 - Synaptics Incorporated)
Theft Recovery for HP ProtectTools (HKLM-x32\...\InstallShield_{ADC70B7A-530B-46E3-8384-48D22681A41E}) (Version: 6.0.0.33 - Hewlett-Packard Company)
Theft Recovery for HP ProtectTools (x32 Version: 6.0.0.33 - Hewlett-Packard Company) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
Validity Fingerprint Sensor Driver (HKLM\...\{FFC3E41D-2C2B-45B7-9AD9-5EA19572DD26}) (Version: 4.3.117.0 - Validity Sensors, Inc.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinZip 18.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DF}) (Version: 18.0.10661 - WinZip Computing, S.L. )
Wondershare Data Recovery(Build 4.6.1.3) (HKLM-x32\...\{FEA3976F-D621-45F3-AFBD-E812A1F2F00D}_is1) (Version: 4.6.1.3 - Wondershare Software Co.,Ltd.)
Xobni Core (x32 Version: 1.0.0 - Xobni, Inc.) Hidden
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-1967446285-4052042257-1953947229-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Karner\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1967446285-4052042257-1953947229-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Karner\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll (Google Inc.)
==================== Wiederherstellungspunkte =========================
16-08-2015 17:53:12 Windows Update
18-08-2015 08:59:33 Windows Update
18-08-2015 20:17:20 Windows Update
19-08-2015 17:17:00 Windows Update
25-08-2015 09:17:40 Windows Update
25-08-2015 09:29:20 Removed Bonjour
25-08-2015 18:01:28 Removed Java 8 Update 25
25-08-2015 18:14:48 Removed LPT System Updater Service
25-08-2015 18:24:53 Windows Update
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {068811E7-4924-45A3-B097-01345AA85C31} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {091535C8-09ED-4D16-BA82-336198C54C64} - System32\Tasks\{D1B5A62B-491E-4C77-BA99-4B74DEF58C2A} => Chrome.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/abandoninstall?source=lightinstaller&page=tsProgressBar
Task: {0D6DE50F-90D6-4EAA-B208-C8BA5761CFB0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-16] (Adobe Systems Incorporated)
Task: {1412CECA-C375-4C06-B5D7-18CD9F6F62D9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1967446285-4052042257-1953947229-1001UA => C:\Users\Karner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.)
Task: {19E2CD7A-36CC-4598-8209-E17B268FA073} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {36EB7F2F-93D0-4D71-B085-44AC327D0B28} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-11] (Google Inc.)
Task: {401C6E53-078F-4607-9B6F-2DF3A1EDDA52} - System32\Tasks\{FDE3F9D0-4C8F-4CD8-AE47-81857AB8A49D} => Chrome.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/abandoninstall?source=lightinstaller&page=tsInstall
Task: {42EA683E-0D1F-47C9-8457-71F03C78068D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {5ABD082D-5596-41A2-9390-F90E6A8216D6} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1967446285-4052042257-1953947229-1001Core => C:\Users\Karner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.)
Task: {A784BA3A-385C-4365-B77C-90ACD4E598EF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2015-08-11] (Microsoft)
Task: {B6E46B00-F658-4363-845A-00801C0EB25F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-11] (Google Inc.)
Task: {EE54F4B1-3524-4694-A9E2-FAEABA43FEF2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {EEC01B1E-C1A7-4ED4-A1CE-E8814CBE1438} - System32\Tasks\{073383A0-77F2-429C-8042-EC46BE9BFC53} => Chrome.exe hxxp://ui.skype.com/ui/0/6.1.0.129.272/de/abandoninstall?page=tsProgressBar
Task: {F5E64A06-D5AF-4EC4-9898-237D24880911} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1967446285-4052042257-1953947229-1001Core.job => C:\Users\Karner\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1967446285-4052042257-1953947229-1001UA.job => C:\Users\Karner\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2011-07-18 17:48 - 2011-07-18 17:48 - 00156216 _____ () C:\Program Files\Hewlett-Packard\Pre-Boot Security for HP ProtectTools\BIOSDomainPlugin.dll
2013-02-01 11:39 - 2013-02-01 11:39 - 03401216 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpeHpFve64.dll
2010-12-07 08:17 - 2010-12-07 08:17 - 00204112 _____ () C:\windows\system32\PassThroughOTP.dll
2010-09-06 14:18 - 2010-09-06 14:18 - 01412608 _____ () C:\windows\system32\LIBEAY32.dll
2013-02-01 10:38 - 2013-02-01 10:38 - 00141824 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHostInterface64.dll
2013-02-01 11:26 - 2013-02-01 11:26 - 01956864 _____ () C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcNp64.DLL
2011-09-01 10:13 - 2011-09-01 10:13 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-11-09 19:55 - 2011-11-09 19:55 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-11-03 00:03 - 2011-11-03 00:03 - 00024576 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingResources.dll
2011-10-14 02:01 - 2011-10-14 02:01 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-03-06 15:00 - 2014-03-06 15:00 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\kpcengine.2.3.dll
2014-10-23 13:09 - 2014-10-23 13:09 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9b1cac8d98bd69d3e56a26ff2f96f266\IsdiInterop.ni.dll
2012-02-04 15:19 - 2011-01-13 03:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
AlternateDataStreams: C:\ProgramData\TEMP:09867A8B
AlternateDataStreams: C:\ProgramData\TEMP:115EA582
AlternateDataStreams: C:\ProgramData\TEMP:2B82C0BB
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F
AlternateDataStreams: C:\ProgramData\TEMP:31C9BA96
AlternateDataStreams: C:\ProgramData\TEMP:31F2397C
AlternateDataStreams: C:\ProgramData\TEMP:3393A1CA
AlternateDataStreams: C:\ProgramData\TEMP:3D3F1635
AlternateDataStreams: C:\ProgramData\TEMP:4C5C1DD3
AlternateDataStreams: C:\ProgramData\TEMP:4E6B8D68
AlternateDataStreams: C:\ProgramData\TEMP:506698B2
AlternateDataStreams: C:\ProgramData\TEMP:538B96B5
AlternateDataStreams: C:\ProgramData\TEMP:5A8F8A0C
AlternateDataStreams: C:\ProgramData\TEMP:5C28E25F
AlternateDataStreams: C:\ProgramData\TEMP:5C353220
AlternateDataStreams: C:\ProgramData\TEMP:66F19688
AlternateDataStreams: C:\ProgramData\TEMP:68DE552E
AlternateDataStreams: C:\ProgramData\TEMP:6BD304B9
AlternateDataStreams: C:\ProgramData\TEMP:6FDE1666
AlternateDataStreams: C:\ProgramData\TEMP:7E0EFF7B
AlternateDataStreams: C:\ProgramData\TEMP:80B291A7
AlternateDataStreams: C:\ProgramData\TEMP:80E965A3
AlternateDataStreams: C:\ProgramData\TEMP:81653DC8
AlternateDataStreams: C:\ProgramData\TEMP:871526BA
AlternateDataStreams: C:\ProgramData\TEMP:89A5891E
AlternateDataStreams: C:\ProgramData\TEMP:89C2A42C
AlternateDataStreams: C:\ProgramData\TEMP:8B076EC5
AlternateDataStreams: C:\ProgramData\TEMP:8D565A9B
AlternateDataStreams: C:\ProgramData\TEMP:91486201
AlternateDataStreams: C:\ProgramData\TEMP:A1D3FEF0
AlternateDataStreams: C:\ProgramData\TEMP:A561576B
AlternateDataStreams: C:\ProgramData\TEMP:AE2EA3C2
AlternateDataStreams: C:\ProgramData\TEMP:BD4CC9FB
AlternateDataStreams: C:\ProgramData\TEMP:C7F08EA3
AlternateDataStreams: C:\ProgramData\TEMP:D0757AAB
AlternateDataStreams: C:\ProgramData\TEMP:D3A8AA31
AlternateDataStreams: C:\ProgramData\TEMP:D7C0213D
AlternateDataStreams: C:\ProgramData\TEMP:E81603BC
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30
AlternateDataStreams: C:\ProgramData\TEMP:F264BECE
AlternateDataStreams: C:\ProgramData\TEMP:F6DA3F39
AlternateDataStreams: C:\ProgramData\TEMP:FBFC061F
AlternateDataStreams: C:\ProgramData\TEMP:FDF9B285
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-1967446285-4052042257-1953947229-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Karner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
MSCONFIG\Services: ACDaemon => 3
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AESTFilters => 2
MSCONFIG\Services: Bluetooth Device Manager => 3
MSCONFIG\Services: Bluetooth Media Service => 3
MSCONFIG\Services: Bluetooth OBEX Service => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: FLEXnet Licensing Service => 3
MSCONFIG\Services: FLEXnet Licensing Service 64 => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: McAfee Endpoint Encryption Agent => 2
MSCONFIG\Services: pdfcDispatcher => 2
MSCONFIG\Services: STacSV => 2
MSCONFIG\Services: uArcCapture => 2
MSCONFIG\startupfolder: C:^Users^Karner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk => C:\windows\pss\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: DTRun => c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: Google Update => "C:\Users\Karner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleChromeAutoLaunch_62EF63C3DC09A815C0F2BB9555814766 => "C:\Users\Karner\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MfeEpePcMonitor => "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"
MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Sony PC Companion => "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{42588269-55E3-4799-BAF6-51EC2EB5964B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CEA35843-A934-4488-B8F4-EEAE1A9969D2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7B2F6CA2-E1F4-4256-A1AA-CBA9309DBD8B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D68A3AAC-F1A0-466E-8315-518D209FE712}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{72F2F83C-0D74-4637-B3F7-2D6835F264E5}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0ED66A34-2E5E-45F5-AA1F-CF79D739C7DA}] => (Allow) LPort=2869
FirewallRules: [{204A5EFB-DC6F-4CB7-8547-5CCF936FC991}] => (Allow) LPort=1900
FirewallRules: [{F9CFB0B5-2E03-4C54-93F4-8D18BD2365A7}] => (Allow) C:\Users\Karner\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Fehlerhafte Geräte im Gerätemanager =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (08/26/2015 07:49:40 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (08/26/2015 07:42:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Systemfehler:
=============
Error: (08/26/2015 07:47:05 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (08/26/2015 07:39:34 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
Microsoft Office:
=========================
CodeIntegrity:
===================================
Date: 2015-08-26 08:02:14.358
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:01:39.621
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:01:12.851
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:00:55.344
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:00:53.980
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:00:35.208
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 08:00:33.220
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 07:52:22.502
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 07:46:33.337
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-08-26 07:46:31.987
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\AESTAR64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Speicherinformationen ===========================
Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz
Prozentuale Nutzung des RAM: 46%
Installierter physikalischer RAM: 4030.36 MB
Verfügbarer physikalischer RAM: 2139.18 MB
Summe virtueller Speicher: 10172.56 MB
Verfügbarer virtueller Speicher: 7689.38 MB
==================== Laufwerke ================================
Drive c: () (Fixed) (Total:572.75 GB) (Free:475.4 GB) NTFS ==>[System mit Startkomponenten (eingeholt von lesen Laufwerk)]
Drive e: (HP_RECOVERY) (Fixed) (Total:18.13 GB) (Free:2.76 GB) NTFS ==>[System mit Startkomponenten (eingeholt von lesen Laufwerk)]
Drive f: (HP_TOOLS) (Fixed) (Total:4.98 GB) (Free:2.1 GB) FAT32
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 12DEB3A0)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=572.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=18.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=5 GB) - (Type=0C)
==================== Ende von Addition.txt ============================ Gmer.log Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-26 08:15:37
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST640LM0 rev.2AJ1 596,17GB
Running: y2fv9j2d.exe; Driver: C:\Users\Karner\AppData\Local\Temp\ufdcapog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000752e1401 2 bytes JMP 768bb20b C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000752e1419 2 bytes JMP 768bb336 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000752e1431 2 bytes JMP 76938f39 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000752e144a 2 bytes CALL 76894885 C:\windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000752e14dd 2 bytes JMP 76938832 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000752e14f5 2 bytes JMP 76938a08 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000752e150d 2 bytes JMP 76938728 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000752e1525 2 bytes JMP 76938af2 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000752e153d 2 bytes JMP 768afc98 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000752e1555 2 bytes JMP 768b68df C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000752e156d 2 bytes JMP 76938ff1 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000752e1585 2 bytes JMP 76938b52 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000752e159d 2 bytes JMP 769386ec C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000752e15b5 2 bytes JMP 768afd31 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000752e15cd 2 bytes JMP 768bb2cc C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000752e16b2 2 bytes JMP 76938eb4 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe[3000] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000752e16bd 2 bytes JMP 76938681 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000771e13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000771e1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000771e18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000771e1ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000771e1d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000771e1e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000771e1f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000771e2238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000771e26e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000771e2702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000771e275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000771e27c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000771e2b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000771e2bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000771e30ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000771e3238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 318 00000000771e38ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000771e3923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000771e39f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000771e3f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000771e4041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000771e40b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000771e41f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000771e4234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000771e44a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000771e468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000771e4753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000771e4847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000771e4966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000771e4a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000771e4ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000771e4ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000771e4ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000771e4fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000771e51d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000771e6016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 00000000771e60e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000771e61de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000771e63cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000771e640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000771e6424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000771e647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000771e6c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 00000000771e7be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 00000000771e7c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007722da80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007722dc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007722dc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007722dd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007722de00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007722e430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007722e680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007722eee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074c613cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074c6146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074c616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074c619db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074c619fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4860] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074c61a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000771e13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000771e1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000771e18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000771e1ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000771e1d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000771e1e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000771e1f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000771e2238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000771e26e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000771e2702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000771e275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000771e27c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000771e2b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000771e2bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000771e30ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000771e3238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 318 00000000771e38ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000771e3923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000771e39f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000771e3f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000771e4041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000771e40b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000771e41f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000771e4234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000771e44a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000771e468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000771e4753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000771e4847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000771e4966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000771e4a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000771e4ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000771e4ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000771e4ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000771e4fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000771e51d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000771e6016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 00000000771e60e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000771e61de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000771e63cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000771e640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000771e6424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000771e647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000771e6c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 00000000771e7be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 00000000771e7c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007722da80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007722dc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007722dc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007722dd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007722de00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007722e430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007722e680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007722eee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074c613cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074c6146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074c616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074c619db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074c619fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[2960] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074c61a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000771e13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000771e1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000771e18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000771e1ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000771e1d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000771e1e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000771e1f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000771e2238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000771e26e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000771e2702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000771e275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000771e27c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000771e2b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000771e2bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000771e30ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000771e3238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 318 00000000771e38ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000771e3923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000771e39f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000771e3f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000771e4041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000771e40b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000771e41f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000771e4234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000771e44a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000771e468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000771e4753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000771e4847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000771e4966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000771e4a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000771e4ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000771e4ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000771e4ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000771e4fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000771e51d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000771e6016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 00000000771e60e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000771e61de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000771e63cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000771e640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000771e6424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000771e647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000771e6c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 00000000771e7be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 00000000771e7c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007722da80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007722dc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007722dc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007722dd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007722de00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007722e430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007722e680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007722eee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074c613cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074c6146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074c616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074c619db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074c619fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5600] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074c61a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000771e13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000771e1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000771e18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000771e1ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000771e1d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000771e1e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000771e1f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000771e2238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000771e26e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000771e2702 8 bytes {JMP 0x10}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000771e275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000771e27c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000771e2b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000771e2bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000771e30ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000771e3238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 318 00000000771e38ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000771e3923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000771e39f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000771e3f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000771e4041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000771e40b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000771e41f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000771e4234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000771e44a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000771e468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000771e4753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000771e4847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000771e4966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000771e4a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000771e4ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000771e4ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000771e4ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000771e4fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000771e51d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000771e6016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 00000000771e60e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000771e61de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000771e63cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000771e640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000771e6424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000771e647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000771e6c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 00000000771e7be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 00000000771e7c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007722da80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007722dc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007722dc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007722dd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007722de00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007722e430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007722e680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007722eee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074c613cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074c6146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074c616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074c619db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074c619fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\windows\SysWOW64\regsvr32.exe[5228] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074c61a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000771e13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000771e1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000771e18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000771e1ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000771e1d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000771e1e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000771e1f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000771e2238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000771e26e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000771e2702 8 bytes {JMP 0x10}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000771e275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000771e27c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000771e2b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000771e2bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000771e30ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000771e3238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 318 00000000771e38ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 403 00000000771e3923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000771e39f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000771e3f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000771e4041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000771e40b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000771e41f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000771e4234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000771e44a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000771e468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000771e4753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000771e4847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000771e4966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000771e4a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000771e4ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000771e4ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000771e4ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000771e4fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000771e51d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000771e6016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 00000000771e60e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000771e61de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000771e63cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000771e640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000771e6424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000771e647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000771e6c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 00000000771e7be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 00000000771e7c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007722da80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007722dc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007722dc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007722dd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007722de00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007722e430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007722e680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007722eee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074c613cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074c6146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074c616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074c619db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074c619fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5716] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074c61a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3704:5028] 000007fefb292ae8
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3704:3524] 000007fee3a05648
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3704:4228] 000007fef7df5124
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:4936] 0000000075907587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:5056] 000000006be18aa6
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:4520] 00000000773fc557
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:3696] 00000000774127c1
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:1520] 00000000774127c1
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4900:3644] 00000000774127c1
Thread C:\windows\System32\svchost.exe [2572:5936] 000007fee5dc9688
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\20107afde131
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\20107afde131 (not active ControlSet)
---- EOF - GMER 2.1 ---- |