Monstera | 11.06.2015 13:04 | Hier Gmer.txt Teil 3 Code:
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe[7472] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, 1F, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ff8c5de5ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ff8c5de5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ff8c5de60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ff8c5de64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ff8c5de6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ff8c5de66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ff8c5de8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ff8c5de8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ff8c5de8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ff8c5de8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ff8c5de90ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ff8c5de917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ff8c5de9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ff8c5de9fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ff8c5deaae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ff8c5deab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ff8c5deb2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ff8c5deb33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ff8c5dec4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ff8c5dec5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Libs\DTHelper.exe[7948] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff8c5353e10 7 bytes JMP 00007ff9c3320340
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ff8c5353e20 7 bytes JMP 00007ff9c3320378
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!RegSetValueExW 00007ff8c54039b0 7 bytes JMP 00007ff9c3320420
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ff8c5403ef0 7 bytes JMP 00007ff9c33203b0
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!RegSetValueExA 00007ff8c5403fe0 7 bytes JMP 00007ff9c33203e8
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff8c54306c0 7 bytes JMP 00007ff9c3320298
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff8c5430730 7 bytes JMP 00007ff9c3320308
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff8c5430760 7 bytes JMP 00007ff9c33202d0
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNELBASE.dll!FreeLibrary 00007ff8c33321d0 5 bytes JMP 00007ff9c3320180
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ff8c33329d0 7 bytes JMP 00007ff9c33200d8
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff8c3334310 5 bytes JMP 00007ff9c3320110
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ff8c3338d80 5 bytes JMP 00007ff9c3320148
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\USER32.dll!CreateWindowExW 00007ff8c50e6d90 10 bytes JMP 00007ff9c3320500
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\USER32.dll!EnumDisplayDevicesW 00007ff8c50f74a0 5 bytes JMP 00007ff9c33204c8
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ff8c50f7560 9 bytes JMP 00007ff9c3320458
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\USER32.dll!EnumDisplayDevicesA 00007ff8c5106b10 5 bytes JMP 00007ff9c3320490
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff8c56b1500 8 bytes JMP 00007ff9c33201b8
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff8c56b1750 8 bytes JMP 00007ff9c33201f0
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\SYSTEM32\combase.dll!CoCreateInstance 00007ff8c54cd050 7 bytes JMP 00007ff9c3320228
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe[6092] C:\windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ff8c54fb170 5 bytes JMP 00007ff9c3320260
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff8c5353e10 7 bytes JMP 00007ff9c33202d0
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ff8c5353e20 7 bytes JMP 00007ff9c3320308
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!RegSetValueExW 00007ff8c54039b0 7 bytes JMP 00007ff9c33203b0
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ff8c5403ef0 7 bytes JMP 00007ff9c3320340
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!RegSetValueExA 00007ff8c5403fe0 7 bytes JMP 00007ff9c3320378
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff8c54306c0 7 bytes JMP 00007ff9c3320228
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff8c5430730 7 bytes JMP 00007ff9c3320298
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff8c5430760 7 bytes JMP 00007ff9c3320260
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNELBASE.dll!FreeLibrary 00007ff8c33321d0 5 bytes JMP 00007ff9c3320180
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ff8c33329d0 7 bytes JMP 00007ff9c33200d8
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff8c3334310 5 bytes JMP 00007ff9c3320110
.text C:\Windows\System32\SettingSyncHost.exe[4132] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ff8c3338d80 5 bytes JMP 00007ff9c3320148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ff8c5de5ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ff8c5de5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ff8c5de60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ff8c5de64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ff8c5de6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ff8c5de66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ff8c5de8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ff8c5de8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ff8c5de8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ff8c5de8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ff8c5de90ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ff8c5de917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ff8c5de9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ff8c5de9fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ff8c5deaae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ff8c5deab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ff8c5deb2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ff8c5deb33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ff8c5dec4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ff8c5dec5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4336] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, FD, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ff8c5de5ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ff8c5de5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ff8c5de60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ff8c5de64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ff8c5de6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ff8c5de66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ff8c5de8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ff8c5de8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ff8c5de8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ff8c5de8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ff8c5de90ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ff8c5de917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ff8c5de9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ff8c5de9fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ff8c5deaae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ff8c5deab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ff8c5deb2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ff8c5deb33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ff8c5dec4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ff8c5dec5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4560] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, 28, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ff8c5de5ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ff8c5de5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ff8c5de60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ff8c5de64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ff8c5de6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ff8c5de66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ff8c5de8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ff8c5de8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ff8c5de8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ff8c5de8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ff8c5de90ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ff8c5de917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ff8c5de9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ff8c5de9fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ff8c5deaae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ff8c5deab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ff8c5deb2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ff8c5deb33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ff8c5dec4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ff8c5dec5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, 7A, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4932] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, 7A, FF, 00, 00, 00, ...]
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff8c5353e10 7 bytes JMP 00007ff9c33202d0
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ff8c5353e20 7 bytes JMP 00007ff9c3320308
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!RegSetValueExW 00007ff8c54039b0 7 bytes JMP 00007ff9c33203b0
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ff8c5403ef0 7 bytes JMP 00007ff9c3320340
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!RegSetValueExA 00007ff8c5403fe0 7 bytes JMP 00007ff9c3320378
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff8c54306c0 7 bytes JMP 00007ff9c3320228
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff8c5430730 7 bytes JMP 00007ff9c3320298
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff8c5430760 7 bytes JMP 00007ff9c3320260
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNELBASE.dll!FreeLibrary 00007ff8c33321d0 5 bytes JMP 00007ff9c3320180
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ff8c33329d0 7 bytes JMP 00007ff9c33200d8
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff8c3334310 5 bytes JMP 00007ff9c3320110
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ff8c3338d80 5 bytes JMP 00007ff9c3320148
.text C:\windows\system32\DllHost.exe[5292] C:\windows\SYSTEM32\user32.dll!CreateWindowExW 00007ff8c50e6d90 10 bytes JMP 00007ff9c3320490
.text C:\windows\system32\DllHost.exe[5292] C:\windows\SYSTEM32\user32.dll!EnumDisplayDevicesW 00007ff8c50f74a0 5 bytes JMP 00007ff9c3320458
.text C:\windows\system32\DllHost.exe[5292] C:\windows\SYSTEM32\user32.dll!DisplayConfigGetDeviceInfo 00007ff8c50f7560 1 byte JMP 00007ff9c33203e8
.text C:\windows\system32\DllHost.exe[5292] C:\windows\SYSTEM32\user32.dll!DisplayConfigGetDeviceInfo + 2 00007ff8c50f7562 7 bytes {JMP 0xfffffffffe228e88}
.text C:\windows\system32\DllHost.exe[5292] C:\windows\SYSTEM32\user32.dll!EnumDisplayDevicesA 00007ff8c5106b10 5 bytes JMP 00007ff9c3320420
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff8c56b1500 8 bytes JMP 00007ff9c33201b8
.text C:\windows\system32\DllHost.exe[5292] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff8c56b1750 8 bytes JMP 00007ff9c33201f0
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!K32GetModuleInformation 00007ff8c5353e10 7 bytes JMP 00007ff9c33202d0
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!RegQueryValueExW 00007ff8c5353e20 7 bytes JMP 00007ff9c3320308
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!RegSetValueExW 00007ff8c54039b0 7 bytes JMP 00007ff9c33203b0
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!RegDeleteValueW 00007ff8c5403ef0 7 bytes JMP 00007ff9c3320340
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!RegSetValueExA 00007ff8c5403fe0 7 bytes JMP 00007ff9c3320378
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00007ff8c54306c0 7 bytes JMP 00007ff9c3320228
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!K32GetMappedFileNameW 00007ff8c5430730 7 bytes JMP 00007ff9c3320298
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 00007ff8c5430760 7 bytes JMP 00007ff9c3320260
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNELBASE.dll!FreeLibrary 00007ff8c33321d0 5 bytes JMP 00007ff9c3320180
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ff8c33329d0 7 bytes JMP 00007ff9c33200d8
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff8c3334310 5 bytes JMP 00007ff9c3320110
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ff8c3338d80 5 bytes JMP 00007ff9c3320148
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\SYSTEM32\combase.dll!CoCreateInstance 00007ff8c54cd050 7 bytes JMP 00007ff9c33204c8
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ff8c54fb170 5 bytes JMP 00007ff9c3320500
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\USER32.dll!CreateWindowExW 00007ff8c50e6d90 10 bytes JMP 00007ff9c3320490
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\USER32.dll!EnumDisplayDevicesW 00007ff8c50f74a0 5 bytes JMP 00007ff9c3320458
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ff8c50f7560 1 byte JMP 00007ff9c33203e8
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\USER32.dll!DisplayConfigGetDeviceInfo + 2 00007ff8c50f7562 7 bytes {JMP 0xfffffffffe228e88}
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\USER32.dll!EnumDisplayDevicesA 00007ff8c5106b10 5 bytes JMP 00007ff9c3320420
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff8c56b1500 8 bytes JMP 00007ff9c33201b8
.text G:\KeePass2.29\KeePass.exe[6464] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff8c56b1750 8 bytes JMP 00007ff9c33201f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ff8c5de5ef1 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ff8c5de5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ff8c5de60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ff8c5de64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ff8c5de6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ff8c5de66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ff8c5de8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ff8c5de8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ff8c5de8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ff8c5de8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ff8c5de90ae 8 bytes {JMP 0xffffffffffffff96}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ff8c5de917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ff8c5de9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ff8c5de9fcd 8 bytes {JMP 0xffffffffffffffaf}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ff8c5deaae0 8 bytes {JMP 0xffffffffffffffcd}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ff8c5deab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ff8c5deb2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ff8c5deb33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ff8c5dec4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ff8c5dec5b0 8 bytes {JMP 0xffffffffffffffc7}
.text ... * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ff8c5ded0d3 8 bytes {JMP 0xffffffffffffffef}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ff8c5ded10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ff8c5ded57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ff8c5ded6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ff8c5ded888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ff8c5ded944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ff8c5dedba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ff8c5dedd58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ff8c5dee073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ff8c5dee124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ff8c5dee160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ff8c5deeb74 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ff8c5defe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ff8c5df009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ff8c5df015b 8 bytes [70, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ff8c5df1438 8 bytes [40, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ff8c5df15e6 8 bytes [30, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ff8c5df1877 8 bytes [20, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ff8c5df1a2d 8 bytes [10, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ff8c5df1c35 8 bytes [00, 6C, 1A, FE, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ff8c5e61290 8 bytes {JMP QWORD [RIP-0x6fe5e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ff8c5e61410 8 bytes {JMP QWORD [RIP-0x6fe30]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ff8c5e61440 8 bytes {JMP QWORD [RIP-0x712eb]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ff8c5e61560 8 bytes {JMP QWORD [RIP-0x70c1e]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ff8c5e61610 8 bytes {JMP QWORD [RIP-0x71122]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff8c5e61cd0 8 bytes {JMP QWORD [RIP-0x700a1]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ff8c5e61fd0 8 bytes {JMP QWORD [RIP-0x705a9]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ff8c5e62850 8 bytes {JMP QWORD [RIP-0x70fdf]}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 7
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 00000000776625d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077662714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077662961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[6612] C:\windows\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077662bd3 8 bytes [DC, 6A, 1A, FE, 00, 00, 00, ...]
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff8c5353e10 7 bytes JMP 00007ff9c33202d0
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ff8c5353e20 7 bytes JMP 00007ff9c3320308
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!RegSetValueExW 00007ff8c54039b0 7 bytes JMP 00007ff9c33203b0
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ff8c5403ef0 7 bytes JMP 00007ff9c3320340
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!RegSetValueExA 00007ff8c5403fe0 7 bytes JMP 00007ff9c3320378
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff8c54306c0 7 bytes JMP 00007ff9c3320228
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff8c5430730 7 bytes JMP 00007ff9c3320298
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff8c5430760 7 bytes JMP 00007ff9c3320260
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNELBASE.dll!FreeLibrary 00007ff8c33321d0 5 bytes JMP 00007ff9c3320180
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ff8c33329d0 7 bytes JMP 00007ff9c33200d8
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff8c3334310 5 bytes JMP 00007ff9c3320110
.text C:\windows\splwow64.exe[7744] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ff8c3338d80 5 bytes JMP 00007ff9c3320148
.text C:\windows\splwow64.exe[7744] C:\windows\system32\USER32.dll!CreateWindowExW 00007ff8c50e6d90 10 bytes JMP 00007ff9c3320490
.text C:\windows\splwow64.exe[7744] C:\windows\system32\USER32.dll!EnumDisplayDevicesW 00007ff8c50f74a0 5 bytes JMP 00007ff9c3320458
.text C:\windows\splwow64.exe[7744] C:\windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ff8c50f7560 1 byte JMP 00007ff9c33203e8
.text C:\windows\splwow64.exe[7744] C:\windows\system32\USER32.dll!DisplayConfigGetDeviceInfo + 2 00007ff8c50f7562 7 bytes {JMP 0xfffffffffe228e88}
.text C:\windows\splwow64.exe[7744] C:\windows\system32\USER32.dll!EnumDisplayDevicesA 00007ff8c5106b10 5 bytes JMP 00007ff9c3320420
.text C:\windows\splwow64.exe[7744] C:\windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff8c56b1500 8 bytes JMP 00007ff9c33201b8
.text C:\windows\splwow64.exe[7744] C:\windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff8c56b1750 8 bytes JMP 00007ff9c33201f0
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 18 0000000000aa1950 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 137 0000000000aa19c7 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 202 0000000000aa1a08 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 310 0000000000aa1a74 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 572 0000000000aa1b7a 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 767 0000000000aa1c3d 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 788 0000000000aa1c52 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 800 0000000000aa1c5e 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 836 0000000000aa1c82 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE!wdGetApplicationObject + 920 0000000000aa1cd6 1 byte [AA]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ff8c5de4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ff8c5de4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ff8c5de5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ff8c5de53ff 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ff8c5de579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE[860] C:\windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ff8c5de5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] |