LordDampf | 21.10.2014 16:13 | 2. gmer Teil 2 Code:
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\taskhost.exe[1368] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\Explorer.EXE[2156] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3556] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3772] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\igfxsrvc.exe[3812] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075351465 2 bytes [35, 75]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753514bb 2 bytes [35, 75]
.text ... * 2
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\system32\SearchIndexer.exe[5028] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 00000000770613d0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 6 00000000770613d6 8 bytes [F5, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077061480 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 6 0000000077061486 8 bytes [8D, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077061520 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 6 0000000077061526 8 bytes [E5, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077061530 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 6 0000000077061536 8 bytes [7D, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077061570 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 6 0000000077061576 8 bytes [5D, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770615e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 6 00000000770615e6 8 bytes [B9, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 00000000770617e0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread + 6 00000000770617e6 8 bytes [99, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077061800 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 6 0000000077061806 8 bytes [51, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000770618b0 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 6 00000000770618b6 8 bytes [21, 36, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 0000000077061d80 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess + 6 0000000077061d86 8 bytes [C9, 33, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile 0000000077061e00 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteFile + 6 0000000077061e06 8 bytes [05, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey 0000000077061e10 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteKey + 6 0000000077061e16 8 bytes [6D, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey 0000000077061e40 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteValueKey + 6 0000000077061e46 8 bytes [41, 34, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx 0000000077062200 5 bytes [FF, 15, 00, 00, 00]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKeyEx + 6 0000000077062206 8 bytes [31, 35, B7, 74, 00, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtRenameKey 0000000077062690 14 bytes {CALL QWORD [RIP+0x0]}
---- Processes - GMER 2.1 ----
Library C:\Users\Maria\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Maria\AppData\Roaming\Dropbox\bin\Dropbox.exe [3992](2014-09-13 00:20:58) 0000000003eb0000
Library c:\users\maria\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxuk1so.dll (*** suspicious ***) @ C:\Users\Maria\AppData\Roaming\Dropbox\bin\Dropbox.exe [3992](2014-10-19 20:37:21) 00000000042f0000
Library C:\Users\Maria\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Maria\AppData\Roaming\Dropbox\bin\Dropbox.exe [3992](2013-08-23 19:01:44) 000000006b3a0000
Library C:\Users\Maria\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Maria\AppData\Roaming\Dropbox\bin\Dropbox.exe [3992] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 000000006aa10000
---- EOF - GMER 2.1 ---- |