gorbiWTF | 28.08.2015 02:45 | Gmer.log Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-27 21:25:27
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000063 WDC_WD10 rev.80.0 931,51GB
Running: y2fv9j2d.exe; Driver: C:\Users\Karner\AppData\Local\Temp\uxriipog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075c91401 2 bytes JMP 7646b20b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075c91419 2 bytes JMP 7646b336 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075c91431 2 bytes JMP 764e8f39 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075c9144a 2 bytes CALL 76444885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075c914dd 2 bytes JMP 764e8832 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075c914f5 2 bytes JMP 764e8a08 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075c9150d 2 bytes JMP 764e8728 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075c91525 2 bytes JMP 764e8af2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075c9153d 2 bytes JMP 7645fc98 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075c91555 2 bytes JMP 764668df C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075c9156d 2 bytes JMP 764e8ff1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075c91585 2 bytes JMP 764e8b52 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075c9159d 2 bytes JMP 764e86ec C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075c915b5 2 bytes JMP 7645fd31 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075c915cd 2 bytes JMP 7646b2cc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075c916b2 2 bytes JMP 764e8eb4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075c916bd 2 bytes JMP 764e8681 C:\Windows\syswow64\kernel32.dll
? C:\Windows\system32\mssprxy.dll [412] entry point in ".rdata" section 000000006e1f71e6
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076f813ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076f81544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076f818ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076f81ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076f81d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076f81e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076f81f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000076f82238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076f826e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076f82702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076f8275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076f827c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076f82b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076f82bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076f830ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076f83238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076f838ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076f83923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076f839f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076f83f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076f84041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076f840b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076f841f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076f84234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000076f844a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076f8468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076f84753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076f84847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076f84966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076f84a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076f84ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076f84ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076f84ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076f84fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000076f851d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076f86016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000076f860e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076f861de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076f863cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076f8640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076f86424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076f8647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076f86c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076f87be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076f87c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076fcda80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076fcdc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076fcdc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076fcdd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076fcde00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076fce430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076fce680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076fceee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736a13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000736a146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736a16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736a19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736a19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe[3908] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000736a1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076f813ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076f81544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076f818ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076f81ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076f81d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076f81e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076f81f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000076f82238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076f826e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076f82702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076f8275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076f827c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076f82b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076f82bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076f830ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076f83238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076f838ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076f83923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076f839f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076f83f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076f84041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076f840b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076f841f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076f84234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000076f844a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076f8468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076f84753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076f84847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076f84966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076f84a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076f84ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076f84ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076f84ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076f84fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000076f851d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076f86016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000076f860e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076f861de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076f863cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076f8640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076f86424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076f8647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076f86c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076f87be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076f87c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076fcda80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076fcdc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076fcdc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076fcdd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076fcde00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076fce430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076fce680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076fceee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736a13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000736a146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736a16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736a19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736a19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000736a1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075c91401 2 bytes JMP 7646b20b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075c91419 2 bytes JMP 7646b336 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075c91431 2 bytes JMP 764e8f39 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075c9144a 2 bytes CALL 76444885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075c914dd 2 bytes JMP 764e8832 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075c914f5 2 bytes JMP 764e8a08 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075c9150d 2 bytes JMP 764e8728 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075c91525 2 bytes JMP 764e8af2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075c9153d 2 bytes JMP 7645fc98 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075c91555 2 bytes JMP 764668df C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075c9156d 2 bytes JMP 764e8ff1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075c91585 2 bytes JMP 764e8b52 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075c9159d 2 bytes JMP 764e86ec C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075c915b5 2 bytes JMP 7645fd31 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075c915cd 2 bytes JMP 7646b2cc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075c916b2 2 bytes JMP 764e8eb4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\TeamViewer.exe[5308] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075c916bd 2 bytes JMP 764e8681 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076f813ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076f81544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076f818ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076f81ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076f81d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076f81e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076f81f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000076f82238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076f826e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076f82702 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076f8275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076f827c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076f82b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076f82bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076f830ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076f83238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076f838ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076f83923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076f839f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076f83f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076f84041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076f840b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076f841f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076f84234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000076f844a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076f8468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076f84753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076f84847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076f84966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076f84a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076f84ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076f84ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076f84ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076f84fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000076f851d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076f86016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000076f860e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076f861de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076f863cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076f8640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076f86424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076f8647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076f86c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076f87be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076f87c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076fcda80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076fcdc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076fcdc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076fcdd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076fcde00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076fce430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076fce680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076fceee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736a13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000736a146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736a16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736a19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736a19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\TeamViewer\tv_w32.exe[2036] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000736a1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076f813ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076f81544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076f818ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076f81ba8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076f81d25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076f81e8f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076f81f75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000076f82238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076f826e0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076f82702 8 bytes {JMP 0x10}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076f8275f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076f827c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076f82b8b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076f82bd7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076f830ab 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076f83238 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076f838ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076f83923 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076f839f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076f83f90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076f84041 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076f840b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076f841f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076f84234 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 0000000076f844a1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076f8468c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076f84753 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076f84847 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076f84966 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076f84a90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076f84ae3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076f84ce5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076f84ee0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076f84fe7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 0000000076f851d3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076f86016 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!EtwEventProviderEnabled + 198 0000000076f860e6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076f861de 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076f863cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076f8640d 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076f86424 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076f8647c 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076f86c46 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076f87be1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076f87c67 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076fcda80 8 bytes {JMP QWORD [RIP-0x46e40]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076fcdc00 8 bytes {JMP QWORD [RIP-0x465e2]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076fcdc30 8 bytes {JMP QWORD [RIP-0x47829]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076fcdd50 8 bytes {JMP QWORD [RIP-0x478da]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076fcde00 8 bytes {JMP QWORD [RIP-0x479e2]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076fce430 8 bytes {JMP QWORD [RIP-0x467cf]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076fce680 8 bytes {JMP QWORD [RIP-0x46aa5]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076fceee0 8 bytes {JMP QWORD [RIP-0x47403]}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736a13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000736a146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736a16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736a19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736a19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Karner\Desktop\3\y2fv9j2d.exe[5164] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000736a1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |