Okay ;)
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-10-2014 01
Ran by Kay at 2014-10-29 00:56:03
Running from C:\Users\Kay\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.5 64-bit (HKLM\...\{19BBD0F3-7A31-480D-8A23-19AE28035E9C}) (Version: 5.5.0 - Adobe Systems Incorporated)
Advanced SystemCare 7 (HKLM-x32\...\Advanced SystemCare 7_is1) (Version: 7.4.0 - IObit)
Broadcom Card Reader Driver Installer (HKLM\...\{67AA948F-8D83-4566-B84A-7CAABCF64E3F}) (Version: 16.0.2.8 - Broadcom Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Dritek Radio Controller (HKLM-x32\...\RadioController) (Version: 2.02.2001.0803 - Dritek System Inc.)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.41 - Dropbox, Inc.)
ETDWare PS/2-X64 11.6.27.201_WHQL (HKLM\...\Elantech) (Version: 11.6.27.201 - ELAN Microelectronic Corp.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3304 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.0.4.30 - IObit)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Java Auto Updater (x32 Version: 2.8.25.18 - Oracle Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4}) (Version: 15.0.0.463 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.0.463 - Kaspersky Lab) Hidden
LRTimelapse 3.4 (HKLM-x32\...\{7413A137-4748-4073-BD2D-F87716D37D6C}_is1) (Version: 3.4 - Gunther Wegner)
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PDF Split And Merge Basic (HKLM\...\{9A40D2F8-9458-458B-95E3-B57797C574E1}) (Version: 2.2.3 - Andrea Vacondio)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.310.0 - Tracker Software Products Ltd)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7040 - Realtek Semiconductor Corp.)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft)
Shark007 Advanced Codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 4.8.5 - Shark007)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
WinRAR 5.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
x64 Components v4.8.5 (HKLM\...\Advanced x64Components_is1) (Version: 4.8.5 - Shark007)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-238317821-3679567806-3060715667-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Kay\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
25-10-2014 09:42:52 Installed Broadcom Card Reader Driver Installer.
28-10-2014 23:31:14 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {150757E0-465C-4A66-87C1-C92EEE2B0E29} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {1E913310-C522-42C5-BC25-E0EC07A9CA44} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {31FA8B4D-80D0-4D6A-AEEF-7B86B7E71156} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\ScheduleWepCEIP => C:\Windows\system32\WepsqmTask.exe [2014-03-18] (Microsoft Corporation)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {35DCC5CB-9D69-43D0-A7A4-40D16685361C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3E327632-D7A0-4E6F-BAC8-9FF8347699BF} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {62521F60-F8E1-40AB-A19A-BAC98A1A370D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {68B1B39F-C96F-4BC9-8467-21AC558B7363} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-03] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {831060E5-83FD-4176-B456-2EC2C8715504} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {889F783D-0560-43E9-AD61-60C5E984D8D0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9D663017-A702-44C1-8345-411050F762C1} - System32\Tasks\ASC7_SkipUac_Kay => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2014-08-22] (IObit)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A74BDED5-32DA-4AA4-AE99-85E27181FC26} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-25] (Adobe Systems Incorporated)
Task: {B20CEBC6-B64C-45D1-B604-28F46A30B466} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {B27BA022-3F97-469B-94F5-B5D316161882} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)
Task: {B6E0A4A8-41C8-4008-847D-A61ADB9C6EA8} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {B93A9E77-00B9-44BC-92E3-5CDB64EF898E} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe [2014-08-20] (IObit)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F15426F3-5916-4395-9687-C117D2E2AA1F} - System32\Tasks\Uninstaller_SkipUac_Kay => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-10-28] (IObit)
Task: {F9F36A6D-F262-4C1D-A7E7-ED8D9BCDA816} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {FB1E9EA8-8D79-4B1B-8DEC-50E2B0FC772A} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ASC7_SkipUac_Kay.job => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_Kay.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
==================== Loaded Modules (whitelisted) =============
2014-05-20 23:33 - 2014-05-20 23:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-10-25 11:11 - 2007-09-02 12:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe
2014-09-25 19:44 - 2014-09-25 19:44 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2014-10-28 23:07 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll
2014-03-06 14:00 - 2014-03-06 14:00 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\kpcengine.2.3.dll
2014-10-25 10:46 - 2013-09-04 00:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-10-28 23:07 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madExcept_.bpl
2014-10-28 23:07 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madBasic_.bpl
2014-10-28 23:07 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madDisAsm_.bpl
2014-10-28 23:07 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\webres.dll
2014-10-25 11:11 - 2007-09-02 12:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll
2014-10-29 00:43 - 2014-10-29 00:43 - 00043008 _____ () c:\users\kay\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvlav3u.dll
2014-10-25 16:59 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Kay\AppData\Roaming\Dropbox\bin\libcef.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-238317821-3679567806-3060715667-500 - Administrator - Disabled)
Gast (S-1-5-21-238317821-3679567806-3060715667-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-238317821-3679567806-3060715667-1003 - Limited - Enabled)
Kay (S-1-5-21-238317821-3679567806-3060715667-1001 - Administrator - Enabled) => C:\Users\Kay
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/29/2014 00:31:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (10/28/2014 11:57:23 PM) (Source: Perflib) (EventID: 1017) (User: )
Description: Outlook
Error: (10/28/2014 11:57:23 PM) (Source: Perflib) (EventID: 1021) (User: )
Description: Outlook8
Error: (10/28/2014 11:26:38 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (10/28/2014 11:26:34 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (10/28/2014 11:26:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (10/28/2014 11:26:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (10/28/2014 11:05:21 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (10/25/2014 00:11:53 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0x8007232B
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0ab82d54-47f4-4acb-818c-cc5bf0ecb649;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (10/25/2014 00:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Fehler bei der Lizenzaktivierung (slui.exe). Fehlercode:
hr=0x8007232B
Befehlszeilenargumente:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0ab82d54-47f4-4acb-818c-cc5bf0ecb649;NotificationInterval=1440;Trigger=NetworkAvailable
System errors:
=============
Error: (10/29/2014 00:44:39 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.27
registriert werden. Der Computer mit IP-Adresse 192.168.1.17 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.
Error: (10/29/2014 00:32:11 AM) (Source: DCOM) (EventID: 10010) (User: RazZzoR)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (10/29/2014 00:31:41 AM) (Source: DCOM) (EventID: 10010) (User: RazZzoR)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (10/28/2014 11:19:02 PM) (Source: DCOM) (EventID: 10010) (User: RazZzoR)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (10/28/2014 11:07:36 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "Advanced SystemCare Service 7" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (10/28/2014 11:07:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "LiveUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (10/28/2014 10:46:06 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%2147952449
Error: (10/28/2014 10:46:06 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%2147952449
Error: (10/28/2014 10:26:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/28/2014 10:26:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Microsoft Office Sessions:
=========================
Error: (10/29/2014 00:31:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1
Error: (10/28/2014 11:57:23 PM) (Source: Perflib) (EventID: 1017) (User: )
Description: Outlook
Error: (10/28/2014 11:57:23 PM) (Source: Perflib) (EventID: 1021) (User: )
Description: Outlook8
Error: (10/28/2014 11:26:38 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Kay\Downloads\esetsmartinstaller_deu.exe
Error: (10/28/2014 11:26:34 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Kay\Downloads\esetsmartinstaller_deu.exe
Error: (10/28/2014 11:26:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Kay\Downloads\esetsmartinstaller_deu.exe
Error: (10/28/2014 11:26:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Kay\Downloads\esetsmartinstaller_deu.exe
Error: (10/28/2014 11:05:21 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Kay\Downloads\esetsmartinstaller_deu.exe
Error: (10/25/2014 00:11:53 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0x8007232BRuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0ab82d54-47f4-4acb-818c-cc5bf0ecb649;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (10/25/2014 00:10:29 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: hr=0x8007232BRuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0ab82d54-47f4-4acb-818c-cc5bf0ecb649;NotificationInterval=1440;Trigger=NetworkAvailable
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-3517U CPU @ 1.90GHz
Percentage of memory in use: 17%
Total physical RAM: 8010.35 MB
Available physical RAM: 6579.66 MB
Total Pagefile: 9930.35 MB
Available Pagefile: 8295.51 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:238.13 GB) (Free:188.95 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 274A8937)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=238.1 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Gemer Part1: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-10-29 01:07:56
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002c Crucial_CT256MX100SSD1 rev.MU01 238,47GB
Running: Gmer-19357.exe; Driver: C:\Users\Kay\AppData\Local\Temp\pxddrpow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960001c7e00 15 bytes [00, F1, F6, 01, 40, 8F, 6C, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff960001c7e10 11 bytes [00, 6D, FC, FF, 00, A3, C3, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\System32\spoolsv.exe[1396] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff902eb169a 4 bytes {JMP 0x4}
.text C:\Windows\System32\spoolsv.exe[1396] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff902eb16a2 4 bytes {JMP 0x4}
.text C:\Windows\System32\spoolsv.exe[1396] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff902eb181a 4 bytes {JMP 0x4}
.text C:\Windows\System32\spoolsv.exe[1396] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff902eb1832 4 bytes {JMP 0x4}
.text C:\Windows\System32\igfxpers.exe[4156] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff902eb169a 4 bytes {JMP 0x4}
.text C:\Windows\System32\igfxpers.exe[4156] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff902eb16a2 4 bytes {JMP 0x4}
.text C:\Windows\System32\igfxpers.exe[4156] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff902eb181a 4 bytes {JMP 0x4}
.text C:\Windows\System32\igfxpers.exe[4156] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff902eb1832 4 bytes {JMP 0x4}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ff902ed2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ff902ed2d14 8 bytes {JMP 0xffffffffffffffd8}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ff902ed2ee8 16 bytes {JMP 0xffffffffffffffb8}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ff902ed3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ff902ed3878 8 bytes {JMP 0xffffffffffffffd3}
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ff902ed425c 8 bytes {JMP 0xffffffffffffffbb}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ff902ed4a2b 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ff902ed4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ff902ed4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ff902ed5030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ff902ed511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ff902ed6693 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff902ed6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ff902ed6b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ff902ed740f 8 bytes {JMP 0xffffffffffffffe8}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ff902ed75c7 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ff902eda8b3 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ff902eda8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ff902eda9c4 8 bytes {JMP 0xffffffffffffffe1}
.text ... * 3
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ff902edad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ff902edb157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ff902edb218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ff902edb57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ff902edb648 8 bytes [10, 6A, F8, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ff902edb88c 8 bytes [F0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ff902edb98c 8 bytes [E0, 69, F8, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ff902edbc38 8 bytes [B0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff902edbe94 8 bytes [A0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff902f51740 8 bytes {JMP QWORD [RIP-0x75dba]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff902f518c0 8 bytes {JMP QWORD [RIP-0x75eda]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff902f518f0 8 bytes {JMP QWORD [RIP-0x762ae]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff902f51a10 8 bytes {JMP QWORD [RIP-0x7618a]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff902f51ac0 8 bytes {JMP QWORD [RIP-0x76403]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff902f52180 8 bytes {JMP QWORD [RIP-0x762f2]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff902f52480 8 bytes {JMP QWORD [RIP-0x7684e]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff902f52d00 8 bytes {JMP QWORD [RIP-0x771f6]}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b5137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b51512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b51551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b51577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b51784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b517c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b517e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b51834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b51841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b51a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b52ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b52c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4700] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b52c43 8 bytes [7C, 68, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ff902ed2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ff902ed2d14 8 bytes {JMP 0xffffffffffffffd8}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ff902ed2ee8 16 bytes {JMP 0xffffffffffffffb8}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ff902ed3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ff902ed3878 8 bytes {JMP 0xffffffffffffffd3}
.text ... * 2
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ff902ed425c 8 bytes {JMP 0xffffffffffffffbb}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ff902ed4a2b 8 bytes {JMP 0xffffffffffffffde}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ff902ed4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ff902ed4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ff902ed5030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ff902ed511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ff902ed6693 8 bytes {JMP 0xffffffffffffffde}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff902ed6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ff902ed6b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ff902ed740f 8 bytes {JMP 0xffffffffffffffe8}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ff902ed75c7 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ff902eda8b3 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ff902eda8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ff902eda9c4 8 bytes {JMP 0xffffffffffffffe1}
.text ... * 3
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ff902edad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ff902edb157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ff902edb218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ff902edb57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ff902edb648 8 bytes [10, 6A, F8, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ff902edb88c 8 bytes [F0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ff902edb98c 8 bytes [E0, 69, F8, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ff902edbc38 8 bytes [B0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff902edbe94 8 bytes [A0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff902f51740 8 bytes {JMP QWORD [RIP-0x75dba]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff902f518c0 8 bytes {JMP QWORD [RIP-0x75eda]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff902f518f0 8 bytes {JMP QWORD [RIP-0x762ae]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff902f51a10 8 bytes {JMP QWORD [RIP-0x7618a]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff902f51ac0 8 bytes {JMP QWORD [RIP-0x76403]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff902f52180 8 bytes {JMP QWORD [RIP-0x762f2]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff902f52480 8 bytes {JMP QWORD [RIP-0x7684e]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff902f52d00 8 bytes {JMP QWORD [RIP-0x771f6]}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b5137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b51512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b51551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b51577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b51784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b517c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b517e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b51834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b51841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b51a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b52ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b52c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Kay\AppData\Roaming\Dropbox\bin\Dropbox.exe[4908] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b52c43 8 bytes [7C, 68, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ff902ed2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ff902ed2d14 8 bytes {JMP 0xffffffffffffffd8}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ff902ed2ee8 16 bytes {JMP 0xffffffffffffffb8}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ff902ed3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ff902ed3878 8 bytes {JMP 0xffffffffffffffd3}
.text ... * 2
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ff902ed425c 8 bytes {JMP 0xffffffffffffffbb}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ff902ed4a2b 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ff902ed4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ff902ed4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ff902ed5030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ff902ed511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ff902ed6693 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff902ed6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ff902ed6b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ff902ed740f 8 bytes {JMP 0xffffffffffffffe8}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ff902ed75c7 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ff902eda8b3 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ff902eda8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ff902eda9c4 8 bytes {JMP 0xffffffffffffffe1}
.text ... * 3
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ff902edad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ff902edb157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ff902edb218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ff902edb57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ff902edb648 8 bytes [10, 6A, 39, 7E, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ff902edb88c 8 bytes [F0, 69, 39, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ff902edb98c 8 bytes [E0, 69, 39, 7E, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ff902edbc38 8 bytes [B0, 69, 39, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff902edbe94 8 bytes [A0, 69, 39, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff902f51740 8 bytes {JMP QWORD [RIP-0x75dba]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff902f518c0 8 bytes {JMP QWORD [RIP-0x75eda]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff902f518f0 8 bytes {JMP QWORD [RIP-0x762ae]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff902f51a10 8 bytes {JMP QWORD [RIP-0x7618a]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff902f51ac0 8 bytes {JMP QWORD [RIP-0x76403]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff902f52180 8 bytes {JMP QWORD [RIP-0x762f2]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff902f52480 8 bytes {JMP QWORD [RIP-0x7684e]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff902f52d00 8 bytes {JMP QWORD [RIP-0x771f6]}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b5137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b51512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b51551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b51577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b51784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b517c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b517e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b51834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b51841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b51a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b52ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b52c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\RadioController\RfBtnHelper.exe[5844] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b52c43 8 bytes [7C, 68, 39, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ff902ed2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ff902ed2d14 8 bytes {JMP 0xffffffffffffffd8}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ff902ed2ee8 16 bytes {JMP 0xffffffffffffffb8}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ff902ed3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ff902ed3878 8 bytes {JMP 0xffffffffffffffd3}
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ff902ed425c 8 bytes {JMP 0xffffffffffffffbb}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ff902ed4a2b 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ff902ed4a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ff902ed4cfc 8 bytes {JMP 0xffffffffffffffb1}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ff902ed5030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ff902ed511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ff902ed6693 8 bytes {JMP 0xffffffffffffffde}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff902ed6964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ff902ed6b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ff902ed740f 8 bytes {JMP 0xffffffffffffffe8}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ff902ed75c7 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ff902eda8b3 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ff902eda8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ff902eda9c4 8 bytes {JMP 0xffffffffffffffe1}
.text ... * 3
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ff902edad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ff902edb157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ff902edb218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ff902edb57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ff902edb648 8 bytes [10, 6A, 14, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ff902edb88c 8 bytes [F0, 69, 14, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ff902edb98c 8 bytes [E0, 69, 14, 7F, 00, 00, 00, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ff902edbc38 8 bytes [B0, 69, 14, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff902edbe94 8 bytes [A0, 69, 14, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff902f51740 8 bytes {JMP QWORD [RIP-0x75dba]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff902f518c0 8 bytes {JMP QWORD [RIP-0x75eda]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff902f518f0 8 bytes {JMP QWORD [RIP-0x762ae]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff902f51a10 8 bytes {JMP QWORD [RIP-0x7618a]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff902f51ac0 8 bytes {JMP QWORD [RIP-0x76403]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff902f52180 8 bytes {JMP QWORD [RIP-0x762f2]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff902f52480 8 bytes {JMP QWORD [RIP-0x7684e]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff902f52d00 8 bytes {JMP QWORD [RIP-0x771f6]}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077b5137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077b51512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077b51551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077b51577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077b51784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077b517c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077b517e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077b51834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077b51841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077b51a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077b52ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077b52c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5868] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077b52c43 8 bytes [7C, 68, 14, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe[7088] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ff902ed2bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe[7088] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ff902ed2d14 8 bytes {JMP 0xffffffffffffffd8}
.text C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe[7088] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ff902ed2ee8 16 bytes {JMP 0xffffffffffffffb8}
.text C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe[7088] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ff902ed3757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe[7088] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ff902ed3878 8 bytes {JMP 0xffffffffffffffd3}
.text ... * 2 |