Code:
Alles auswählen Aufklappen ATTFilter
Code:
Alles auswählen Aufklappen ATTFilter
Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-04-16 23:40:49
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000031 WDC_WD10JPVT-75A1YT0 rev.01.01A01 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Thomas\AppData\Local\Temp\awdiypow.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffa84b83e10 7 bytes JMP 00007ffb825a02d0
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!RegQueryValueExW 00007ffa84b83e20 7 bytes JMP 00007ffb825a0308
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExW 00007ffa84c339b0 7 bytes JMP 00007ffb825a03b0
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!RegDeleteValueW 00007ffa84c33ef0 7 bytes JMP 00007ffb825a0340
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExA 00007ffa84c33fe0 7 bytes JMP 00007ffb825a0378
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffa84c606c0 7 bytes JMP 00007ffb825a0228
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffa84c60730 7 bytes JMP 00007ffb825a0298
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ffa84c60760 7 bytes JMP 00007ffb825a0260
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ffa825b21d0 5 bytes JMP 00007ffb825a0180
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ffa825b29d0 7 bytes JMP 00007ffb825a00d8
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffa825b4310 5 bytes JMP 00007ffb825a0110
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ffa825b8d80 5 bytes JMP 00007ffb825a0148
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffa82b66d90 10 bytes JMP 00007ffb825a0490
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ffa82b774a0 5 bytes JMP 00007ffb825a0458
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffa82b77560 1 byte JMP 00007ffb825a03e8
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo + 2 00007ffa82b77562 7 bytes {JMP 0xffffffffffa28e88}
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ffa82b86b10 5 bytes JMP 00007ffb825a0420
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffa83051500 8 bytes JMP 00007ffb825a01b8
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffa83051750 8 bytes JMP 00007ffb825a01f0
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\dxgi.dll!CreateDXGIFactory 00007ffa7f837750 5 bytes JMP 00007ffb7f6800d8
.text C:\WINDOWS\system32\dwm.exe[976] C:\WINDOWS\system32\dxgi.dll!CreateDXGIFactory1 00007ffa7f838ee0 5 bytes JMP 00007ffb7f680110
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2960] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077632bd3 8 bytes [DC, 6A, 48, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe[2632] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077632bd3 8 bytes [DC, 6A, 95, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe[3980] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077632bd3 8 bytes [DC, 6A, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2664] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077632bd3 8 bytes [DC, 6A, 9D, 7F, 00, 00, 00, ...]
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleInformation 00007ffa84b83e10 7 bytes JMP 00007ffb825a03b0
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!RegQueryValueExW 00007ffa84b83e20 7 bytes JMP 00007ffb825a03e8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExW 00007ffa84c339b0 7 bytes JMP 00007ffb825a0490
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!RegDeleteValueW 00007ffa84c33ef0 7 bytes JMP 00007ffb825a0420
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExA 00007ffa84c33fe0 7 bytes JMP 00007ffb825a0458
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!K32EnumProcessModulesEx 00007ffa84c606c0 7 bytes JMP 00007ffb825a0308
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!K32GetMappedFileNameW 00007ffa84c60730 7 bytes JMP 00007ffb825a0378
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleFileNameExW 00007ffa84c60760 7 bytes JMP 00007ffb825a0340
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ffa825b21d0 5 bytes JMP 00007ffb825a0180
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ffa825b29d0 7 bytes JMP 00007ffb825a00d8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffa825b4310 5 bytes JMP 00007ffb825a0110
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ffa825b8d80 5 bytes JMP 00007ffb825a0148
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\SYSTEM32\combase.dll!CoCreateInstance 00007ffa84dad050 7 bytes JMP 00007ffb825a0228
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffa84ddb170 5 bytes JMP 00007ffb825a0260
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffa82b66d90 10 bytes JMP 00007ffb825a0570
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ffa82b774a0 5 bytes JMP 00007ffb825a0538
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffa82b77560 9 bytes JMP 00007ffb825a04c8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ffa82b86b10 5 bytes JMP 00007ffb825a0500
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffa83051500 8 bytes JMP 00007ffb825a01b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffa83051750 8 bytes JMP 00007ffb825a01f0
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\SYSTEM32\d3d9.dll!Direct3DCreate9Ex 00007ffa66f5ead0 5 bytes JMP 00007ffa825a02d0
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[2500] C:\WINDOWS\SYSTEM32\d3d9.dll!Direct3DCreate9 00007ffa66f8eb90 6 bytes JMP 00007ffa825a0298
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe[3004] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077632bd3 8 bytes [DC, 6A, 52, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffa85064b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffa85064f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffa85065206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffa850653ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffa8506579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffa85065954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffa85065ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffa85065f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffa850660ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffa850664d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffa85066616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffa850666cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffa85068397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffa85068a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffa85068d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffa85068e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffa850690ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffa8506917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffa85069d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffa85069fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffa8506aae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffa8506ab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffa8506b2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffa8506b33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffa8506c4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffa8506c5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffa8506d0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffa8506d10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffa8506d57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffa8506d6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffa8506d888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffa8506d944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffa8506dba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffa8506dd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffa8506e073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffa8506e124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffa8506e160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffa8506eb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffa8506fe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffa8507009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffa8507015b 8 bytes [70, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffa85071438 8 bytes [40, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffa850715e6 8 bytes [30, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffa85071877 8 bytes [20, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffa85071a2d 8 bytes [10, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffa85071c35 8 bytes [00, 6C, 47, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffa850e1290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffa850e1410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffa850e1440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffa850e1560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffa850e1610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffa850e1cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffa850e1fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffa850e2850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000776313f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077631583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077631621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077631674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776316d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776316e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077631727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776325d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077632714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077632961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[4020] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595