![]() |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Hallo Liebe Trojaner-Board-Helfer, Seit ich eine VPN-Verbindung zur Uni Koblenz vor einigen Tagen hergestellt habe, treten folgende Erscheinungen auf: Nach klick auf meinen Webbrowser (Chrome) beginnt als erstes ca. 15 sek. lang ein Ladevorgang bevor die Seite tatsächlich anfängt zu laden. Mit meiner Dropbox kann ich überhaupt keine Internetverbindung herstellen ("Keine Internet-Verbindung. Ihr Computer ist offline. ..."). Nachdem ich Chrome und Dropbox wieder neu installiert habe und keinerlei Besserung zu verbuchen war, habe ich eine Systemwiederherstellung versucht. Diese jedoch brachte nach Systemneustart lediglich folgende Fehlermeldung: "Die Systemherstellung wurde nicht erfolgreich ausgeführt. Die Systemdatei und Einstellungen des Computers wurden nicht geändert." Jetzt bin ich der Überzeugung das ich mir vermutlich einen Schädling eingefangen habe. Danke schon einmal im Voraus Liebe Grüße Tim |
Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Hallo Liebe Trojaner-Board-Helfer, Seit ich eine VPN-Verbindung zur Uni Koblenz vor einigen Tagen hergestellt habe, treten folgende Erscheinungen auf: Nach klick auf meinen Webbrowser (Chrome) beginnt als erstes ca. 15 sek. lang ein Ladevorgang bevor die Seite tatsächlich anfängt zu laden. Mit meiner Dropbox kann ich überhaupt keine Internetverbindung herstellen ("Keine Internet-Verbindung. Ihr Computer ist offline. ..."). Nachdem ich Chrome und Dropbox wieder neu installiert habe und keinerlei Besserung zu verbuchen war, habe ich eine Systemwiederherstellung versucht. Diese jedoch brachte nach Systemneustart lediglich folgende Fehlermeldung: "Die Systemherstellung wurde nicht erfolgreich ausgeführt. Die Systemdatei und Einstellungen des Computers wurden nicht geändert." Jetzt bin ich der Überzeugung das ich mir vermutlich einen Schädling eingefangen habe. Danke schon einmal im Voraus Liebe Grüße Tim Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02 |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Vortsetzung: Code: defogger_disable by jpshortstuff (23.02.10.1) Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02 |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Vortsetzung: Code: GMER 2.1.19357 - hxxp://www.gmer.net |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Fortsetzung: [CODE].text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768914dd 2 bytes JMP 76df8802 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768914f5 2 bytes JMP 76df89d8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007689150d 2 bytes JMP 76df86f8 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076891525 2 bytes JMP 76df8ac2 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007689153d 2 bytes JMP 76d6fc78 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076891555 2 bytes JMP 76d768bf C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007689156d 2 bytes JMP 76df8fc1 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076891585 2 bytes JMP 76df8b22 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007689159d 2 bytes JMP 76df86bc C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768915b5 2 bytes JMP 76d6fd11 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768915cd 2 bytes JMP 76d7b2b0 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768916b2 2 bytes JMP 76df8e84 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Microsoft Office\Office14\ONENOTEM.EXE[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768916bd 2 bytes JMP 76df8651 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000773b1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773b18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 00000000773b1ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000773b1bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000773b1d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000773b1e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000773b1f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000773b2248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773b26f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000773b2712 8 bytes {JMP 0x10} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000773b276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773b27d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000773b2b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000773b2be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773b30bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000773b3248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773b37c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773b38b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000773b3a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000773b3fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000773b4061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773b40d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000773b4216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000773b4254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773b44c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773b46ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000773b4773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000773b4867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000773b4986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000773b4ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000773b4b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000773b4d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000773b4f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000773b5007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773b51f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000773b6006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000773b61be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773b63ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773b63ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000773b6404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000773b645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000773b6c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000773fdca0 8 bytes {JMP QWORD [RIP-0x478a2]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000773fde20 8 bytes {JMP QWORD [RIP-0x479ca]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000773fde50 8 bytes {JMP QWORD [RIP-0x47c98]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000773fdf70 8 bytes {JMP QWORD [RIP-0x47b89]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000773fe020 8 bytes {JMP QWORD [RIP-0x47c7a]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000773fe650 8 bytes {JMP QWORD [RIP-0x46b93]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000773fe8a0 8 bytes {JMP QWORD [RIP-0x472a2]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000773ff100 8 bytes {JMP QWORD [RIP-0x484e0]} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000725513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007255146b 8 bytes {JMP 0xffffffffffffffb0} .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000725516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000725519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000725519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000072551a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076d51eee 7 bytes JMP 0000000166694b10 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076d55b85 7 bytes JMP 00000001666954b0 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076d613e1 7 bytes JMP 0000000166694e50 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076d6ea15 7 bytes JMP 0000000166694b00 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076df8e84 7 bytes JMP 00000001666945c0 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076df8f09 5 bytes JMP 0000000166694670 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076df925f 5 bytes JMP 00000001666945d0 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076a01d29 5 bytes JMP 0000000166694580 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076a01dd7 5 bytes JMP 0000000166694540 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076a02ab1 5 bytes JMP 0000000166694680 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076a02d17 5 bytes JMP 0000000166694360 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000770a8a29 5 bytes JMP 0000000166693a40 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000770b4572 5 bytes JMP 00000001666942e0 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000770ce567 5 bytes JMP 0000000166694350 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000770f07d7 5 bytes JMP 0000000166693850 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077107a5c 5 bytes JMP 00000001666942d0 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007549e96b 5 bytes JMP 0000000166693b60 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007549eba5 5 bytes JMP 0000000166693b80 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000756f5ea5 5 bytes JMP 0000000166693a00 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075729d0b 5 bytes JMP 0000000166693990 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076891401 2 bytes JMP 76d7b1ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076891419 2 bytes JMP 76d7b31a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076891431 2 bytes JMP 76df8f09 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007689144a 2 bytes CALL 76d54885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768914dd 2 bytes JMP 76df8802 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768914f5 2 bytes JMP 76df89d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007689150d 2 bytes JMP 76df86f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076891525 2 bytes JMP 76df8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007689153d 2 bytes JMP 76d6fc78 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076891555 2 bytes JMP 76d768bf C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007689156d 2 bytes JMP 76df8fc1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076891585 2 bytes JMP 76df8b22 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007689159d 2 bytes JMP 76df86bc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768915b5 2 bytes JMP 76d6fd11 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768915cd 2 bytes JMP 76d7b2b0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768916b2 2 bytes JMP 76df8e84 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe[3552] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768916bd 2 bytes JMP 76df8651 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000773b1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773b18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 00000000773b1ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000773b1bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000773b1d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000773b1e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000773b1f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000773b2248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773b26f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000773b2712 8 bytes {JMP 0x10} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000773b276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773b27d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000773b2b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000773b2be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773b30bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000773b3248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773b37c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773b38b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000773b3a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000773b3fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000773b4061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773b40d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000773b4216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000773b4254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773b44c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773b46ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000773b4773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000773b4867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000773b4986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000773b4ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000773b4b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000773b4d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000773b4f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000773b5007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773b51f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000773b6006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000773b61be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773b63ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773b63ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000773b6404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000773b645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000773b6c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000773fdca0 8 bytes {JMP QWORD [RIP-0x478a2]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000773fde20 8 bytes {JMP QWORD [RIP-0x479ca]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000773fde50 8 bytes {JMP QWORD [RIP-0x47c98]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000773fdf70 8 bytes {JMP QWORD [RIP-0x47b89]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000773fe020 8 bytes {JMP QWORD [RIP-0x47c7a]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000773fe650 8 bytes {JMP QWORD [RIP-0x46b93]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000773fe8a0 8 bytes {JMP QWORD [RIP-0x472a2]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000773ff100 8 bytes {JMP QWORD [RIP-0x484e0]} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000725513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007255146b 8 bytes {JMP 0xffffffffffffffb0} .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000725516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000725519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000725519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000072551a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076d51eee 7 bytes JMP 0000000166694b10 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076d55b85 7 bytes JMP 00000001666954b0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076d613e1 7 bytes JMP 0000000166694e50 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076d6ea15 7 bytes JMP 0000000166694b00 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076df8e84 7 bytes JMP 00000001666945c0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076df8f09 5 bytes JMP 0000000166694670 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076df925f 5 bytes JMP 00000001666945d0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076a01d29 5 bytes JMP 0000000166694580 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076a01dd7 5 bytes JMP 0000000166694540 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076a02ab1 5 bytes JMP 0000000166694680 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076a02d17 5 bytes JMP 0000000166694360 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007549e96b 5 bytes JMP 0000000166693b60 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007549eba5 5 bytes JMP 0000000166693b80 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000770a8a29 5 bytes JMP 0000000166693a40 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000770b4572 5 bytes JMP 00000001666942e0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000770ce567 5 bytes JMP 0000000166694350 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000770f07d7 5 bytes JMP 0000000166693850 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077107a5c 5 bytes JMP 00000001666942d0 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000756f5ea5 5 bytes JMP 0000000166693a00 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075729d0b 5 bytes JMP 0000000166693990 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076891401 2 bytes JMP 76d7b1ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076891419 2 bytes JMP 76d7b31a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076891431 2 bytes JMP 76df8f09 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007689144a 2 bytes CALL 76d54885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768914dd 2 bytes JMP 76df8802 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768914f5 2 bytes JMP 76df89d8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007689150d 2 bytes JMP 76df86f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076891525 2 bytes JMP 76df8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007689153d 2 bytes JMP 76d6fc78 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076891555 2 bytes JMP 76d768bf C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007689156d 2 bytes JMP 76df8fc1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076891585 2 bytes JMP 76df8b22 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007689159d 2 bytes JMP 76df86bc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768915b5 2 bytes JMP 76d6fd11 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768915cd 2 bytes JMP 76d7b2b0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768916b2 2 bytes JMP 76df8e84 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768916bd 2 bytes JMP 76df8651 C:\Windows\syswow64\kernel32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000773b1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773b18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 00000000773b1ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000773b1bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000773b1d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000773b1e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000773b1f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000773b2248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773b26f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000773b2712 8 bytes {JMP 0x10} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000773b276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773b27d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000773b2b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000773b2be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773b30bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000773b3248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773b37c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773b38b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000773b3a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000773b3fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000773b4061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773b40d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000773b4216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000773b4254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773b44c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773b46ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000773b4773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000773b4867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000773b4986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000773b4ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000773b4b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000773b4d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000773b4f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000773b5007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773b51f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000773b6006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000773b61be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773b63ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773b63ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000773b6404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000773b645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000773b6c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000773fdca0 8 bytes {JMP QWORD [RIP-0x478a2]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000773fde20 8 bytes {JMP QWORD [RIP-0x479ca]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000773fde50 8 bytes {JMP QWORD [RIP-0x47c98]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000773fdf70 8 bytes {JMP QWORD [RIP-0x47b89]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000773fe020 8 bytes {JMP QWORD [RIP-0x47c7a]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000773fe650 8 bytes {JMP QWORD [RIP-0x46b93]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000773fe8a0 8 bytes {JMP QWORD [RIP-0x472a2]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000773ff100 8 bytes {JMP QWORD [RIP-0x484e0]} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000725513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007255146b 8 bytes {JMP 0xffffffffffffffb0} .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000725516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000725519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000725519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000072551a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 0000000076d51eee 7 bytes JMP 0000000166694b10 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 0000000076d55b85 7 bytes JMP 00000001666954b0 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 0000000076d613e1 7 bytes JMP 0000000166694e50 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 0000000076d6ea15 7 bytes JMP 0000000166694b00 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 0000000076df8e84 7 bytes JMP 00000001666945c0 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076df8f09 5 bytes JMP 0000000166694670 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076df925f 5 bytes JMP 00000001666945d0 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076a01d29 5 bytes JMP 0000000166694580 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076a01dd7 5 bytes JMP 0000000166694540 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076a02ab1 5 bytes JMP 0000000166694680 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076a02d17 5 bytes JMP 0000000166694360 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007549e96b 5 bytes JMP 0000000166693b60 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007549eba5 5 bytes JMP 0000000166693b80 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000770a8a29 5 bytes JMP 0000000166693a40 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000770b4572 5 bytes JMP 00000001666942e0 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000770ce567 5 bytes JMP 0000000166694350 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000770f07d7 5 bytes JMP 0000000166693850 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077107a5c 5 bytes JMP 00000001666942d0 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000756f5ea5 5 bytes JMP 0000000166693a00 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075729d0b 5 bytes JMP 0000000166693990 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076891401 2 bytes JMP 76d7b1ef C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076891419 2 bytes JMP 76d7b31a C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076891431 2 bytes JMP 76df8f09 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007689144a 2 bytes CALL 76d54885 C:\Windows\syswow64\KERNEL32.dll .text ... * 9 .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768914dd 2 bytes JMP 76df8802 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768914f5 2 bytes JMP 76df89d8 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007689150d 2 bytes JMP 76df86f8 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076891525 2 bytes JMP 76df8ac2 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007689153d 2 bytes JMP 76d6fc78 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076891555 2 bytes JMP 76d768bf C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007689156d 2 bytes JMP 76df8fc1 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076891585 2 bytes JMP 76df8b22 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007689159d 2 bytes JMP 76df86bc C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768915b5 2 bytes JMP 76d6fd11 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768915cd 2 bytes JMP 76d7b2b0 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768916b2 2 bytes JMP 76df8e84 C:\Windows\syswow64\KERNEL32.dll .text D:\Programme\Treiber\Sound Blaster Cinema\SBCinema.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768916bd 2 bytes JMP 76df8651 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007719a3e0 7 bytes JMP 000000016fff0228 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000771a3f00 5 bytes JMP 000000016fff0180 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000771bfff0 5 bytes JMP 000000016fff01b8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000771cf360 5 bytes JMP 000000016fff0110 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000771f9ab0 7 bytes JMP 000000016fff00d8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077209540 5 bytes JMP 000000016fff0148 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077228860 1 byte JMP 000000016fff01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegSetValueExA + 2 0000000077228862 5 bytes {JMP 0xfffffffff8dc7990} .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd3b3460 7 bytes JMP 000007fffd3a00d8 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd3ca590 6 bytes JMP 000007fffd3a0148 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd3cac00 5 bytes JMP 000007fffd3a0180 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd3cada0 5 bytes JMP 000007fffd3a0110 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe4c89e0 8 bytes JMP 000007fffd3a01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe4cbe40 8 bytes JMP 000007fffd3a01b8 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000773b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000773b1544 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000773b18ce 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 644 00000000773b1ad4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000773b1bb4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000773b1d35 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000773b1e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000773b1f85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000773b2248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000773b26f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 00000000773b2712 8 bytes {JMP 0x10} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 00000000773b276f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 00000000773b27d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 00000000773b2b9b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 00000000773b2be7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 00000000773b30bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 00000000773b3248 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 33 00000000773b37c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 274 00000000773b38b2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 00000000773b3a15 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 00000000773b3fb0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 00000000773b4061 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 00000000773b40d5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 00000000773b4216 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 00000000773b4254 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 609 00000000773b44c1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 00000000773b46ac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 00000000773b4773 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 00000000773b4867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 00000000773b4986 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 00000000773b4ab0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 00000000773b4b03 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 00000000773b4d05 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 00000000773b4f00 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 00000000773b5007 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 483 00000000773b51f3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 00000000773b6006 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 00000000773b61be 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 00000000773b63ac 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 00000000773b63ed 8 bytes [50, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 00000000773b6404 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 00000000773b645c 8 bytes [30, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 00000000773b6c26 8 bytes [20, 6C, F8, 7E, 00, 00, 00, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000773fdca0 8 bytes {JMP QWORD [RIP-0x478a2]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000773fde20 8 bytes {JMP QWORD [RIP-0x479ca]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000773fde50 8 bytes {JMP QWORD [RIP-0x47c98]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000773fdf70 8 bytes {JMP QWORD [RIP-0x47b89]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000773fe020 8 bytes {JMP QWORD [RIP-0x47c7a]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000773fe650 8 bytes {JMP QWORD [RIP-0x46b93]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000773fe8a0 8 bytes {JMP QWORD [RIP-0x472a2]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000773ff100 8 bytes {JMP QWORD [RIP-0x484e0]} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000725513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007255146b 8 bytes {JMP 0xffffffffffffffb0} .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000725516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000725519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000725519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000072551a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076d51eee 7 bytes JMP 0000000166694b10 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076d55b85 7 bytes JMP 00000001666954b0 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076d58769 5 bytes [33, C0, C2, 04, 00] .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076d613e1 7 bytes JMP 0000000166694e50 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076d6ea15 7 bytes JMP 0000000166694b00 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076df8e84 7 bytes JMP 00000001666945c0 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076df8f09 5 bytes JMP 0000000166694670 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076df925f 5 bytes JMP 00000001666945d0 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076a01d29 5 bytes JMP 0000000166694580 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076a01dd7 5 bytes JMP 0000000166694540 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076a02ab1 5 bytes JMP 0000000166694680 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076a02d17 5 bytes JMP 0000000166694360 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000770a8a29 5 bytes JMP 0000000166693a40 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000770b4572 5 bytes JMP 00000001666942e0 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000770ce567 5 bytes JMP 0000000166694350 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000770f07d7 5 bytes JMP 0000000166693850 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077107a5c 5 bytes JMP 00000001666942d0 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007549e96b 5 bytes JMP 0000000166693b60 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007549eba5 5 bytes JMP 0000000166693b80 .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076891401 2 bytes JMP 76d7b1ef C:\Windows\syswow64\kernel32.dll .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076891419 2 bytes JMP 76d7b31a C:\Windows\syswow64\kernel32.dll .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076891431 2 bytes JMP 76df8f09 C:\Windows\syswow64\kernel32.dll .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007689144a 2 bytes CALL 76d54885 C:\Windows\syswow64\kernel32.dll .text ... * 9 |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Fortsetzung: Code: .text C:\Users\Tim\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe[4012] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768914dd 2 bytes JMP 76df8802 C:\Windows\syswow64\kernel32.dll |
Windows 7: Internetprobleme nach VPN Verbindung mit Uni-Server Fortsetzung: (Ende) Code: .text ... * 2 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
MBAM.txt, ADWCleaner, JRT.txt MBAM.txt: Code: Malwarebytes Anti-Malware Code: # AdwCleaner v4.204 - Bericht erstellt 20/05/2015 um 09:52:04 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015 --- --- --- |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Guten Morgen! Der ESET-Scanner hat einige infizierte Dateien gefunden: Code: ESETSmartInstaller@High as downloader log: Code: Results of screen317's Security Check version 1.001 FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015 --- --- --- Die Symptome mit dem ca. 15 sekündigen Ladevorgang beim öffnen des Web-Browsers und die nicht herzustellende Verbindung zur Dropbox sind aber leider immer noch vorhanden. Dies hat vor ein paar Tagen alles noch einwandfrei funktioniert, daher bin ich ein wenig stutzig. :balla: |
Mit welchem Browser hast Du die Probleme? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: D:\Downloads\avira-free-antivir.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloadverhalten überdenken: CHIP-Installer - was ist das? - Anleitungen Du musst den Proxy auch komplett rausnehmen in den Einstellungen, wenn Du nicht in der UNI bist. |
FRST Fixlog: Code: Fix result of Farbar Recovery Scan Tool (x64) Version: 21-05-2015 Nachdem ich die Probleme mit dem VPN festgestellt habe, hab' ich die Verbindung komplett ausgeschaltet. Welche Einstellungen genau muss ich denn noch ändern. Ich dachte ich hätte wieder alles auf den Ursprungszustand zurückgesetzt Wie bekomme ich denn die in dem verlinkten Artikel beschriebenen "Tools" wieder restlos entfernt? Sind Downloads auf Heise.de denn sauberer? |
Solange Du keinen Downloadmanager nutzt sollten das passen. Systemsteuerung > Internetoptionen > Verbindungen > LAN Einstellungen > dort den Proxy raus. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 08:45 Uhr. |
Copyright ©2000-2025, Trojaner-Board