ArmeSocke | 09.03.2015 07:47 | Ok. Danke für die schnelle Antwort.
Defogger und FRST hatte ich ja schon gepostet.
Jetzt noch die fehlenden. Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2015 03
Ran by User at 2015-03-08 21:47:18
Running from C:\Users\User\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 3.1.3042.60281 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.1.3042.60281 - Alcor Micro Corp.) Hidden
Atheros WLAN Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Blood Bowl: Chaos Edition (HKLM-x32\...\Steam App 216890) (Version: - Cyanide Studios)
Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.3.0.145 - Atheros Communications)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.28.50 - Conexant)
Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-3577023336-649988219-1192559642-1001\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.9 - Lenovo)
Energy Management (x32 Version: 7.0.3.9 - Lenovo) Hidden
Gephi 0.8.2 (HKLM-x32\...\{51722911-C391-4118-97BF-B50100D2AB15}_is1) (Version: - Gephi)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Gpg4win (2.2.3) (HKLM-x32\...\GPG4Win) (Version: 2.2.3 - The Gpg4win Project)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1021 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Hardware Accelerated Execution Manager (HKLM\...\{ECCB31F5-435D-4F37-A98D-5854D3C62718}) (Version: 1.1.1 - Intel Corporation)
Intelligent Touchpad (HKLM-x32\...\{FDB0A81A-1173-4B15-BEA4-89FEA0474F17}) (Version: 1.00.0108 - Lenovo)
Java 7 Update 76 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417076FF}) (Version: 7.0.760 - Oracle)
Java SE Development Kit 7 Update 76 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170760}) (Version: 1.7.0.760 - Oracle)
Java(TM) 6 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216045FF}) (Version: 6.0.450 - Oracle)
Java(TM) SE Development Kit 6 Update 45 (HKLM-x32\...\{32A3A4F4-B792-11D6-A78A-00B0D0160450}) (Version: 1.6.0.450 - Oracle)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden
KeePass Password Safe 2.27 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.27 - Dominik Reichl)
Lenovo CAPOSD (HKLM-x32\...\InstallShield_{48F851E7-DD0C-4A35-AD7A-57878023E987}) (Version: 1.0.0.7 - Lenovo)
Lenovo CAPOSD (x32 Version: 1.0.0.7 - Lenovo) Hidden
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.11.1214.1 - Lenovo EasyCamera)
Lenovo Smart Update (HKLM-x32\...\{29B7C0EB-A1E6-4BC3-8344-70EDE4F189F1}) (Version: 1.0.29 - Lenovo Corporation)
Lenovo YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3728 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 3.1.3728 - CyberLink Corp.) Hidden
LenovoDrv_x64 (HKLM\...\{83E68458-AF28-4CA4-8AFC-595A10307290}) (Version: 1.0.00 - Lenovo)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Games for Windows - LIVE (HKLM-x32\...\{F112F66E-25CA-42DD-983C-6118EB38F606}) (Version: 3.0.89.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}) (Version: 3.0.19.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3577023336-649988219-1192559642-1001\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Mozilla Thunderbird 31.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.5.0 (x86 de)) (Version: 31.5.0 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.4 - Notepad++ Team)
Nsd (HKLM-x32\...\{4677B88C-CE16-4CBB-A2CB-B76E9D456C7F}) (Version: 1.0.1.5 - Lenovo)
NVIDIA Grafiktreiber 327.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.62 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.11.1111 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.11.1111 - NVIDIA Corporation)
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
R for Windows 3.1.1 (HKLM\...\R for Windows 3.1.1_is1) (Version: 3.1.1 - R Core Team)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.48.823.2011 - Realtek)
RStudio (HKLM-x32\...\RStudio) (Version: 0.98.1083 - RStudio)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.33.0 - Synaptics Incorporated)
Warhammer® 40,000™: Dawn of War® II - Chaos Rising™ (HKLM-x32\...\Steam App 20570) (Version: - Relic Entertainment)
Warhammer® 40,000™: Dawn of War® II – Retribution™ (HKLM-x32\...\Steam App 56400) (Version: - Relic Entertainment)
Warhammer® 40,000™: Dawn of War® II (HKLM-x32\...\Steam App 15620) (Version: - Relic Entertainment)
Windows Driver Package - Arduino LLC (www.arduino.cc) Arduino USB Driver (01/04/2013 1.0.0.0) (HKLM\...\1E3EA5624DD04BEFECF3FFF6D3A21CCE9CD70A91) (Version: 01/04/2013 1.0.0.0 - Arduino LLC (www.arduino.cc))
Windows Driver Package - Lenovo Corporation (LAD) System (01/13/2012 1.0.0.2) (HKLM\...\5E61CDC4058A17FE9BE3046B1846F3118CD618B1) (Version: 01/13/2012 1.0.0.2 - Lenovo Corporation)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (12/15/2011 7.1.0.1) (HKLM\...\99841829BE839365AA67B2AD0E50D371F59F8A1E) (Version: 12/15/2011 7.1.0.1 - Lenovo)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3577023336-649988219-1192559642-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled.
Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job =>
==================== Loaded Modules (whitelisted) ==============
2013-12-26 18:42 - 2013-12-26 18:42 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2014-05-12 10:49 - 2014-05-12 10:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2008-12-20 02:20 - 2014-04-29 12:19 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2012-03-28 13:34 - 2014-04-29 12:19 - 01509936 _____ () C:\Program Files (x86)\Lenovo\Energy Management\EMWpfUI.dll
2012-03-10 15:31 - 2014-04-29 12:19 - 00012336 _____ () C:\Program Files (x86)\Lenovo\Energy Management\de-DE\EMWpfUI.resources.dll
2008-12-20 02:20 - 2014-04-29 12:19 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2014-04-29 12:10 - 2011-12-08 10:12 - 00291272 _____ () C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe
2014-04-29 12:02 - 2010-10-26 05:40 - 00049056 _____ () C:\Program Files\Conexant\ForteConfig\fmapp.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3577023336-649988219-1192559642-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: KeePass 2 PreLoad => "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
MSCONFIG\startupreg: YouCam Mirage => "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
MSCONFIG\startupreg: YouCam Tray => "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
==================== Accounts: =============================
Admin (S-1-5-21-3577023336-649988219-1192559642-1004 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3577023336-649988219-1192559642-500 - Administrator - Disabled)
Gast (S-1-5-21-3577023336-649988219-1192559642-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3577023336-649988219-1192559642-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-3577023336-649988219-1192559642-1000 - Limited - Enabled) => C:\Users\UpdatusUser
User (S-1-5-21-3577023336-649988219-1192559642-1001 - Limited - Enabled) => C:\Users\User
==================== Faulty Device Manager Devices =============
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth-Peripheriegerät
Description: Bluetooth-Peripheriegerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/08/2015 08:41:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---Get Poicy Open key suc failed with 0, The Code is:0x422.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---Get Poicy Open key suc failed with 0, The Code is:0x422.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---Get Poicy Open key suc failed with 0, The Code is:0x422.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---Get Poicy Open key suc failed with 0, The Code is:0x422.).
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: An error has occurred (---query POLICYVT key success failed with 0, The Code is:0x424.).
System errors:
=============
Error: (03/08/2015 08:40:03 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (03/08/2015 08:39:50 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (03/08/2015 03:25:32 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (03/08/2015 03:25:19 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (03/08/2015 11:15:55 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (03/08/2015 11:15:43 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (03/08/2015 00:44:32 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht.
Error: (03/07/2015 07:41:23 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Error: (03/07/2015 07:41:11 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (03/07/2015 11:15:19 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Der Aufruf "ScRegSetValueExW" ist für "Start" aufgrund folgenden Fehlers fehlgeschlagen:
%%5
Microsoft Office Sessions:
=========================
Error: (03/08/2015 08:41:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---query POLICYVT key success failed with 0, The Code is:0x424.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---Get Poicy Open key suc failed with 0, The Code is:0x422.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---query POLICYVT key success failed with 0, The Code is:0x424.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---Get Poicy Open key suc failed with 0, The Code is:0x422.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---query POLICYVT key success failed with 0, The Code is:0x424.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---Get Poicy Open key suc failed with 0, The Code is:0x422.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---query POLICYVT key success failed with 0, The Code is:0x424.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---Get Poicy Open key suc failed with 0, The Code is:0x422.
Error: (03/08/2015 08:40:02 PM) (Source: NSDSvc) (EventID: 256) (User: )
Description: NSDSvc---query POLICYVT key success failed with 0, The Code is:0x424.
CodeIntegrity Errors:
===================================
Date: 2015-02-14 14:39:21.971
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-14 14:39:21.961
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 18:49:42.513
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 18:49:42.461
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 14:35:54.502
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 14:35:54.502
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 14:35:36.001
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-13 14:35:36.001
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-12 20:03:17.496
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-12 20:03:17.493
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 32%
Total physical RAM: 8052.9 MB
Available physical RAM: 5411.83 MB
Total Pagefile: 16103.99 MB
Available Pagefile: 13296.84 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (Windows7_OS) (Fixed) (Total:420.56 GB) (Free:300.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25.47 GB) (Free:21.56 GB) NTFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ GMER.log (1/2) Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-08 22:00:57
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Admin\AppData\Local\Temp\uwtiquog.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076b0a400 7 bytes JMP 000000016fff0260
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076b13f20 5 bytes JMP 000000016fff01b8
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076b2ffb0 5 bytes JMP 000000016fff01f0
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076b3f2e0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076b69a30 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076b794c0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000076b79630 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076b987e0 7 bytes JMP 000000016fff0228
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefcb62db0 5 bytes JMP 000007fffcb50180
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefcb637d0 7 bytes JMP 000007fffcb500d8
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcb68ef0 6 bytes JMP 000007fffcb50148
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefcb7af60 5 bytes JMP 000007fffcb50110
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefd9f89f0 8 bytes JMP 000007fffcb501f0
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefd9fbe50 8 bytes JMP 000007fffcb501b8
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 0000000076c26c80 5 bytes JMP 000000016fff0308
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 0000000076c2a5b4 5 bytes JMP 000000016fff02d0
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\USER32.dll!CreateWindowExW 0000000076c30810 7 bytes JMP 000000016fff0340
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 0000000076c3ccec 9 bytes JMP 000000016fff0298
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefec97490 11 bytes JMP 000007fffcb50228
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefecabf00 7 bytes JMP 000007fffcb50260
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef85cdc88 5 bytes JMP 000007fff85a00d8
.text C:\Windows\system32\Dwm.exe[2500] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef85cde10 5 bytes JMP 000007fff85a0110
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe[3820] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey 0000000076f1faa8 5 bytes JMP 0000000171d82e30
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe[3820] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000076f20038 5 bytes JMP 0000000171d82df0
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074a61401 2 bytes JMP 7493b21b C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074a61419 2 bytes JMP 7493b346 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074a61431 2 bytes JMP 749b8ea9 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074a6144a 2 bytes CALL 749148ad C:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074a614dd 2 bytes JMP 749b87a2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074a614f5 2 bytes JMP 749b8978 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074a6150d 2 bytes JMP 749b8698 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074a61525 2 bytes JMP 749b8a62 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074a6153d 2 bytes JMP 7492fca8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074a61555 2 bytes JMP 749368ef C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074a6156d 2 bytes JMP 749b8f61 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074a61585 2 bytes JMP 749b8ac2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074a6159d 2 bytes JMP 749b865c C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074a615b5 2 bytes JMP 7492fd41 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074a615cd 2 bytes JMP 7493b2dc C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074a616b2 2 bytes JMP 749b8e24 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe[3888] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074a616bd 2 bytes JMP 749b85f1 C:\Windows\syswow64\KERNEL32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076d21398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d2143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076d21594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d2191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076d21bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d21d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d21edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076d21fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d227b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d227d2 8 bytes {JMP 0x10}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d2282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076d22898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d22d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076d22d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d2323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076d233c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d23a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d23ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d23b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d24190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076d24241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076d242b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076d243f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076d24434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076d245d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076d246d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076d24a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076d24b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076d24c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076d24d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076d24ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076d24ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076d250f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076d252f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076d253f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076d255e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076d264d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076d2668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076d2687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076d268bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076d268d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076d2692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076d27166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076d27dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076d27e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076d71380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076d71500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076d71530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d71650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076d71700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d71d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076d71f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d727e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736913cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007369146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736916d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736919db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736919fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073691a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074a61401 2 bytes JMP 7493b21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074a61419 2 bytes JMP 7493b346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074a61431 2 bytes JMP 749b8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074a6144a 2 bytes CALL 749148ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074a614dd 2 bytes JMP 749b87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074a614f5 2 bytes JMP 749b8978 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074a6150d 2 bytes JMP 749b8698 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074a61525 2 bytes JMP 749b8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074a6153d 2 bytes JMP 7492fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074a61555 2 bytes JMP 749368ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074a6156d 2 bytes JMP 749b8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074a61585 2 bytes JMP 749b8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074a6159d 2 bytes JMP 749b865c C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074a615b5 2 bytes JMP 7492fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074a615cd 2 bytes JMP 7493b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074a616b2 2 bytes JMP 749b8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[4708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074a616bd 2 bytes JMP 749b85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076d21398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d2143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076d21594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d2191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076d21bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d21d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d21edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076d21fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d227b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d227d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d2282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076d22898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d22d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076d22d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d2323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076d233c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d23a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d23ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d23b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d24190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076d24241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076d242b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076d243f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076d24434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076d245d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076d246d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076d24a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076d24b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076d24c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076d24d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076d24ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076d24ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076d250f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076d252f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076d253f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076d255e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076d264d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076d2668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076d2687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076d268bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076d268d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076d2692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076d27166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076d27dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076d27e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076d71380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076d71500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076d71530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d71650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076d71700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d71d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076d71f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d727e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736913cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007369146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736916d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736919db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736919fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe[4224] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073691a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076d21398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d2143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076d21594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d2191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076d21bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d21d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d21edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076d21fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d227b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d227d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d2282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076d22898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d22d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076d22d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d2323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076d233c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d23a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d23ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d23b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d24190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076d24241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076d242b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076d243f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076d24434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076d245d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076d246d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076d24a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076d24b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076d24c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076d24d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076d24ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076d24ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076d250f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076d252f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076d253f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000076d255e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000076d264d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000076d2668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000076d2687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000076d268bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000076d268d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000076d2692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000076d27166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000076d27dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000076d27e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076d71380 8 bytes {JMP QWORD [RIP-0x4a220]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076d71500 8 bytes {JMP QWORD [RIP-0x49cef]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076d71530 8 bytes {JMP QWORD [RIP-0x4ac62]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d71650 8 bytes {JMP QWORD [RIP-0x4a80f]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076d71700 8 bytes {JMP QWORD [RIP-0x4adda]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d71d30 8 bytes {JMP QWORD [RIP-0x49edf]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076d71f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d727e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000736913cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007369146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000736916d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000736919db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000736919fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4388] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000073691a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000076d21398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d2143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000076d21594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d2191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000076d21bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d21d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d21edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000076d21fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d227b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d227d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d2282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000076d22898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d22d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000076d22d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d2323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000076d233c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d23a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d23ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d23b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d24190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000076d24241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000076d242b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000076d243f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000076d24434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000076d245d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000076d246d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000076d24a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000076d24b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000076d24c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000076d24d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000076d24ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000076d24ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000076d250f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000076d252f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6832] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000076d253f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] |