Hab doch noch Gmer geschafft - dabei wurden mir 2 Fehlermeldungen angezeigt.
1) C:\Windows\system32\config\system: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird
2) C:\Users\*****\ntuser.dat: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-10-26 07:37:06
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002f SAMSUNG_MZNTD256HAGL-00000 rev.DXT2300Q 238,47GB
Running: of3gspmf.exe; Driver: C:\Users\*****\AppData\Local\Temp\kwlyypow.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffc26b73e10 7 bytes JMP 00007ffd264502d0
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!RegQueryValueExW 00007ffc26b73e20 7 bytes JMP 00007ffd26450308
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExW 00007ffc26c239b0 7 bytes JMP 00007ffd264503b0
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!RegDeleteValueW 00007ffc26c23ef0 7 bytes JMP 00007ffd26450340
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExA 00007ffc26c23fe0 7 bytes JMP 00007ffd26450378
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffc26c506c0 7 bytes JMP 00007ffd26450228
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffc26c50730 7 bytes JMP 00007ffd26450298
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ffc26c50760 7 bytes JMP 00007ffd26450260
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ffc264621d0 5 bytes JMP 00007ffd26450180
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ffc264629d0 7 bytes JMP 00007ffd264500d8
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffc26464310 5 bytes JMP 00007ffd26450110
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ffc26468900 5 bytes JMP 00007ffd26450148
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffc28a76d90 10 bytes JMP 00007ffd26450490
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ffc28a874a0 5 bytes JMP 00007ffd26450458
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffc28a87560 1 byte JMP 00007ffd264503e8
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo + 2 00007ffc28a87562 7 bytes {JMP 0xfffffffffd9c8e88}
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ffc28a96b10 5 bytes JMP 00007ffd26450420
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffc27161500 8 bytes JMP 00007ffd264501b8
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffc27161750 8 bytes JMP 00007ffd264501f0
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\System32\dxgi.dll!CreateDXGIFactory 00007ffc1f5a7750 5 bytes JMP 00007ffd1f5900d8
.text C:\WINDOWS\System32\dwm.exe[4692] C:\WINDOWS\System32\dxgi.dll!CreateDXGIFactory1 00007ffc1f5a8ee0 5 bytes JMP 00007ffd1f590110
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, 45, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, 45, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, 45, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, 45, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, 45, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe[7448] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, 07, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, 07, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, 07, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, 07, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, 07, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe[1780] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, 82, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, 82, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, 82, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, 82, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, 82, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[7204] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, C6, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, C6, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, C6, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, C6, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, C6, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe[980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, 1E, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, 1E, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, 1E, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, 1E, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, 1E, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2096] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, 21, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, 21, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, 21, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, 21, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, 21, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe[5660] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe[5716] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[696] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[668] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleInformation 00007ffc26b73e10 7 bytes JMP 00007ffd264503b0
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!RegQueryValueExW 00007ffc26b73e20 7 bytes JMP 00007ffd264503e8
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExW 00007ffc26c239b0 7 bytes JMP 00007ffd26450490
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!RegDeleteValueW 00007ffc26c23ef0 7 bytes JMP 00007ffd26450420
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExA 00007ffc26c23fe0 7 bytes JMP 00007ffd26450458
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!K32EnumProcessModulesEx 00007ffc26c506c0 7 bytes JMP 00007ffd26450308
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!K32GetMappedFileNameW 00007ffc26c50730 7 bytes JMP 00007ffd26450378
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleFileNameExW 00007ffc26c50760 7 bytes JMP 00007ffd26450340
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\SYSTEM32\combase.dll!CoCreateInstance 00007ffc26ced050 7 bytes JMP 00007ffd26450228
.text C:\Program Files\Sony\VAIO Care\VCSystemTray.exe[2204] C:\WINDOWS\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffc26d1b170 5 bytes JMP 00007ffd26450260
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleInformation 00007ffc26b73e10 7 bytes JMP 00007ffd264503b0
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!RegQueryValueExW 00007ffc26b73e20 7 bytes JMP 00007ffd264503e8
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExW 00007ffc26c239b0 7 bytes JMP 00007ffd26450490
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!RegDeleteValueW 00007ffc26c23ef0 7 bytes JMP 00007ffd26450420
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!RegSetValueExA 00007ffc26c23fe0 7 bytes JMP 00007ffd26450458
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!K32EnumProcessModulesEx 00007ffc26c506c0 7 bytes JMP 00007ffd26450308
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!K32GetMappedFileNameW 00007ffc26c50730 7 bytes JMP 00007ffd26450378
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNEL32.dll!K32GetModuleFileNameExW 00007ffc26c50760 7 bytes JMP 00007ffd26450340
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ffc264621d0 5 bytes JMP 00007ffd26450180
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ffc264629d0 7 bytes JMP 00007ffd264500d8
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffc26464310 5 bytes JMP 00007ffd26450110
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ffc26468900 5 bytes JMP 00007ffd26450148
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\SYSTEM32\combase.dll!CoCreateInstance 00007ffc26ced050 7 bytes JMP 00007ffd26450228
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffc26d1b170 5 bytes JMP 00007ffd26450260
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffc28a76d90 10 bytes JMP 00007ffd26450570
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ffc28a874a0 5 bytes JMP 00007ffd26450538
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffc28a87560 9 bytes JMP 00007ffd264504c8
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ffc28a96b10 5 bytes JMP 00007ffd26450500
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffc27161500 8 bytes JMP 00007ffd264501b8
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffc27161750 8 bytes JMP 00007ffd264501f0
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\SYSTEM32\d3d9.dll!Direct3DCreate9Ex 00007ffc1b72ead0 5 bytes JMP 00007ffc264502d0
.text C:\Program Files\Sony\VAIO Care\VCAdmin.exe[7660] C:\WINDOWS\SYSTEM32\d3d9.dll!Direct3DCreate9 00007ffc1b75eb90 6 bytes JMP 00007ffc26450298
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\PROGRA~1\Sony\VAIOCA~1\Iolo\IOLOTO~1.EXE[3408] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc28f64b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc28f64f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc28f65216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc28f6540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc28f657af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc28f65964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc28f65f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc28f65f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc28fe12a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc28fe1420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc28fe1450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc28fe1570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc28fe1620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc28fe1ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc28fe1fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc28fe2860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 00000000773f13f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 00000000773f1583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 00000000773f1621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 00000000773f1674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773f16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000773f16e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*****\Desktop\of3gspmf.exe[8104] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 00000000773f1727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [8096:4116] fffff9600082f2d0
Thread C:\WINDOWS\Explorer.EXE [4892:3128] 00007ffc0d83e630
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [6472:4888] 0000000000f3a794
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [6472:7092] 0000000000f34980
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |