Gmer-Log Hier ist mein Gmer.txt: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-04-28 19:42:40
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Corsair_ rev.5.02 111.79GB
Running: u8xquexn.exe; Driver: C:\Users\RON~1\AppData\Local\Temp\kwtdypog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077501401 2 bytes JMP 769db1ef C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077501419 2 bytes JMP 769db31a C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077501431 2 bytes JMP 76a58f09 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007750144a 2 bytes CALL 769b4885 C:\windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000775014dd 2 bytes JMP 76a58802 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000775014f5 2 bytes JMP 76a589d8 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007750150d 2 bytes JMP 76a586f8 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077501525 2 bytes JMP 76a58ac2 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007750153d 2 bytes JMP 769cfc78 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077501555 2 bytes JMP 769d68bf C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007750156d 2 bytes JMP 76a58fc1 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077501585 2 bytes JMP 76a58b22 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007750159d 2 bytes JMP 76a586bc C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000775015b5 2 bytes JMP 769cfd11 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000775015cd 2 bytes JMP 769db2b0 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000775016b2 2 bytes JMP 76a58e84 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2072] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000775016bd 2 bytes JMP 76a58651 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\SysWOW64\WSOCK32.dll!recv + 82 000000006df417fa 2 bytes CALL 769b11a9 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\SysWOW64\WSOCK32.dll!recvfrom + 88 000000006df41860 2 bytes CALL 769b11a9 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\SysWOW64\WSOCK32.dll!setsockopt + 98 000000006df41942 2 bytes JMP 75507089 C:\windows\syswow64\WS2_32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\SysWOW64\WSOCK32.dll!setsockopt + 109 000000006df4194d 2 bytes JMP 7550cba6 C:\windows\syswow64\WS2_32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077501401 2 bytes JMP 769db1ef C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077501419 2 bytes JMP 769db31a C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077501431 2 bytes JMP 76a58f09 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007750144a 2 bytes CALL 769b4885 C:\windows\syswow64\kernel32.dll
.text ... * 9
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000775014dd 2 bytes JMP 76a58802 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000775014f5 2 bytes JMP 76a589d8 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007750150d 2 bytes JMP 76a586f8 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077501525 2 bytes JMP 76a58ac2 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007750153d 2 bytes JMP 769cfc78 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077501555 2 bytes JMP 769d68bf C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007750156d 2 bytes JMP 76a58fc1 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077501585 2 bytes JMP 76a58b22 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007750159d 2 bytes JMP 76a586bc C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000775015b5 2 bytes JMP 769cfd11 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000775015cd 2 bytes JMP 769db2b0 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000775016b2 2 bytes JMP 76a58e84 C:\windows\syswow64\kernel32.dll
.text C:\windows\SysWOW64\PnkBstrA.exe[2460] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000775016bd 2 bytes JMP 76a58651 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077501401 2 bytes JMP 769db1ef C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077501419 2 bytes JMP 769db31a C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077501431 2 bytes JMP 76a58f09 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007750144a 2 bytes CALL 769b4885 C:\windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000775014dd 2 bytes JMP 76a58802 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000775014f5 2 bytes JMP 76a589d8 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007750150d 2 bytes JMP 76a586f8 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077501525 2 bytes JMP 76a58ac2 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007750153d 2 bytes JMP 769cfc78 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077501555 2 bytes JMP 769d68bf C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007750156d 2 bytes JMP 76a58fc1 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077501585 2 bytes JMP 76a58b22 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007750159d 2 bytes JMP 76a586bc C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000775015b5 2 bytes JMP 769cfd11 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000775015cd 2 bytes JMP 769db2b0 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000775016b2 2 bytes JMP 76a58e84 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2204] C:\windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000775016bd 2 bytes JMP 76a58651 C:\windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773513ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077351544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773518ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077351ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077351bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077351d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077351e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077351f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077352248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773526f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077352712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007735276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773527d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077352b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077352be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773530bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077353248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773537c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773538b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077353a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077353fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077354061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773540d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077354216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077354254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773544c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773546ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077354773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077354867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077354986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077354ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077354b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077354d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077354f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077355007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773551f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077356006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000773561be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773563ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773563ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077356404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007735645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077356c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007739dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007739de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007739de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007739df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007739e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007739e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007739e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007739f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074df13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074df146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074df16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074df19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074df19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5144] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074df1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773513ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077351544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773518ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077351ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077351bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077351d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077351e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077351f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077352248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773526f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077352712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007735276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773527d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077352b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077352be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773530bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077353248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773537c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773538b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077353a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077353fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077354061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773540d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077354216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077354254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773544c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773546ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077354773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077354867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077354986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077354ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077354b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077354d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077354f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077355007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773551f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077356006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000773561be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773563ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773563ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077356404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007735645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077356c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007739dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007739de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007739de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007739df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007739e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007739e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007739e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007739f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074df13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074df146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074df16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074df19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074df19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5560] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074df1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773513ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077351544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773518ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077351ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077351bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077351d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077351e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077351f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077352248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773526f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077352712 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007735276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773527d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077352b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077352be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773530bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077353248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773537c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773538b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077353a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077353fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077354061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773540d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077354216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077354254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773544c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773546ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077354773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077354867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077354986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077354ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077354b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077354d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077354f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077355007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773551f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077356006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000773561be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773563ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773563ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077356404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007735645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077356c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007739dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007739de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007739de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007739df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007739e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007739e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007739e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007739f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074df13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074df146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074df16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074df19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074df19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5480] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074df1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773513ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077351544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773518ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 0000000077351ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077351bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077351d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077351e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077351f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 0000000077352248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773526f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077352712 8 bytes {JMP 0x10}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 000000007735276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773527d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077352b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077352be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773530bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077353248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773537c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773538b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077353a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077353fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077354061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773540d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077354216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077354254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773544c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773546ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077354773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077354867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077354986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077354ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077354b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077354d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077354f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077355007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773551f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077356006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!atol + 194 00000000773561be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773563ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773563ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077356404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 000000007735645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077356c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007739dca0 8 bytes {JMP QWORD [RIP-0x478a2]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 000000007739de20 8 bytes {JMP QWORD [RIP-0x479ca]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007739de50 8 bytes {JMP QWORD [RIP-0x47c98]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007739df70 8 bytes {JMP QWORD [RIP-0x47b89]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 000000007739e020 8 bytes {JMP QWORD [RIP-0x47c7a]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007739e650 8 bytes {JMP QWORD [RIP-0x46b93]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 000000007739e8a0 8 bytes {JMP QWORD [RIP-0x472a2]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007739f100 8 bytes {JMP QWORD [RIP-0x484e0]}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074df13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074df146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074df16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074df19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074df19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Àron\Desktop\u8xquexn.exe[6180] C:\windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074df1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Processes - GMER 2.1 ----
Process \\?\C:\windows\system32\wbem\WMIADAP.EXE (*** suspicious ***) @ \\?\C:\windows\system32\wbem\WMIADAP.EXE [6500] (WMI Reverse Performance Adapter Maintenance Utility/Microsoft Corporation)(2009-07-13 23:47:22) 00000000ff410000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\KLIF\Parameters@LastFileRevision 262151
---- EOF - GMER 2.1 ----
Áron Horváth |