FrankW187 | 21.10.2015 19:31 | GMER Teil1 Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-10-21 16:58:41
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\0000008d ADATA___ rev.5.0. 238,47GB
Running: 5c8nd3vo.exe; Driver: C:\Users\Frank\AppData\Local\Temp\kxldapog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2304] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2616] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770e2ab1 5 bytes JMP 0000000100c8fa56
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe[4900] C:\Windows\SYSTEM32\ntdll.dll!DbgBreakPoint 00000000774fcc90 3 bytes [8B, 40, 30]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Frank\AppData\Roaming\Spotify\SpotifyWebHelper.exe[4972] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[4628] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4620] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe[4716] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe[2512] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe[5136] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
? C:\Windows\system32\mssprxy.dll [6080] entry point in ".rdata" section 00000000737071e6
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[6204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\sysWOW64\wbem\wmiprvse.exe[6980] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe[6952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 0000000074e519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000074e51a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077661401 2 bytes JMP 771bb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077661419 2 bytes JMP 771bb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077661431 2 bytes JMP 77238fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007766144a 2 bytes CALL 7719489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000776614dd 2 bytes JMP 772388c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000776614f5 2 bytes JMP 77238aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007766150d 2 bytes JMP 772387ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077661525 2 bytes JMP 77238b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007766153d 2 bytes JMP 771afca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077661555 2 bytes JMP 771b68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007766156d 2 bytes JMP 77239089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077661585 2 bytes JMP 77238bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007766159d 2 bytes JMP 7723877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000776615b5 2 bytes JMP 771afd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000776615cd 2 bytes JMP 771bb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000776616b2 2 bytes JMP 77238f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe[6712] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000776616bd 2 bytes JMP 77238713 C:\Windows\syswow64\kernel32.dll
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 00000000774b13ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 00000000774b1544 8 bytes [60, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 00000000774b18ce 8 bytes [50, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 00000000774b1ba8 8 bytes [40, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 00000000774b1d25 8 bytes [30, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 00000000774b1e8f 8 bytes [20, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 00000000774b1f75 8 bytes [10, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 680 00000000774b2238 8 bytes [00, 6E, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 00000000774b26e0 8 bytes [F0, 6D, F8, 7E, 00, 00, 00, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000774fda80 8 bytes {JMP QWORD [RIP-0x4bd61]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00000000774fdc00 8 bytes {JMP QWORD [RIP-0x4bd77]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000774fdc30 8 bytes {JMP QWORD [RIP-0x4c6f2]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000774fdd50 8 bytes {JMP QWORD [RIP-0x4c1ae]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00000000774fde00 8 bytes {JMP QWORD [RIP-0x4c538]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00000000774fe430 8 bytes {JMP QWORD [RIP-0x4bd56]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00000000774fe680 8 bytes {JMP QWORD [RIP-0x4c44e]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774feee0 8 bytes {JMP QWORD [RIP-0x4cf71]}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 0000000074e513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 0000000074e5146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 0000000074e516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 0000000074e519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\scan\5c8nd3vo.exe[1612] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 |