timdividuell | 03.11.2015 14:40 | Gmer 1 Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-11-03 12:31:00
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000038 rev. 0,00MB
Running: Gmer-19357.exe; Driver: C:\Users\***VLK~1\AppData\Local\Temp\fxldypog.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff9600011a300 15 bytes [00, 0B, F2, 01, 00, 06, 6C, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff9600011a310 8 bytes [00, D7, FB, FF, 00, D3, CD, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, C5, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, C5, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, C5, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, C5, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, C5, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dell\Dell Data Protection\Authentication\Bin\DPAgent.exe[7676] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, 16, 7F, 00, 00, 00, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, 16, 7F, 00, 00, 00, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, 16, 7F, 00, 00, 00, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, 16, 7F, 00, 00, 00, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, 16, 7F, 00, 00, 00, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Windows\SysWOW64\rundll32.exe[8952] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8964] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\*** *******\AppData\Local\Akamai\netsession_win.exe[8972] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_adjust_path + 125 00000000633cb41d 4 bytes [98, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_adjust_path + 250 00000000633cb49a 4 bytes [98, E1, ED, 6F]
.text ... * 5
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_adjust_path_source + 125 00000000633cb83d 4 bytes [98, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_adjust_path_source + 266 00000000633cb8ca 4 bytes [98, E1, ED, 6F]
.text ... * 5
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_record + 359 00000000633cbd57 4 bytes [98, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!csync_rename_record + 679 00000000633cbe97 4 bytes [98, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!_ZNSt8_Rb_treeISsSt4pairIKSsSsESt10_Select1stIS2_ESt4lessISsESaIS2_EE22_M_emplace_hint_uniqueIIRKSt21piecewise_construct_tSt5tupleIIOSsEESD_IIEEEEESt17_Rb_tree_iteratorIS2_ESt23_Rb_tree_const_iteratorIS2_EDpOT_ + 38 000000006344ab66 4 bytes [A4, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!_ZNSt8_Rb_treeISsSt4pairIKSsSsESt10_Select1stIS2_ESt4lessISsESaIS2_EE22_M_emplace_hint_uniqueIIRKSt21piecewise_construct_tSt5tupleIIOSsEESD_IIEEEEESt17_Rb_tree_iteratorIS2_ESt23_Rb_tree_const_iteratorIS2_EDpOT_ + 48 000000006344ab70 4 bytes [A4, E1, ED, 6F]
.text ... * 3
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!_ZNSt8_Rb_treeISsSt4pairIKSsSsESt10_Select1stIS2_ESt4lessISsESaIS2_EE8_M_eraseEPSt13_Rb_tree_nodeIS2_E + 40 000000006344b0a8 4 bytes [98, E1, ED, 6F]
.text C:\Program Files (x86)\ownCloud\owncloud.exe[9084] C:\Program Files (x86)\ownCloud\libocsync.dll!_ZNSt8_Rb_treeISsSt4pairIKSsSsESt10_Select1stIS2_ESt4lessISsESaIS2_EE8_M_eraseEPSt13_Rb_tree_nodeIS2_E + 91 000000006344b0db 4 bytes [98, E1, ED, 6F]
.text C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[9044] C:\Windows\system32\KERNEL32.DLL!SetUnhandledExceptionFilter 00007ffc7a2747d0 5 bytes [90, 33, C0, 90, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, BF, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, BF, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, BF, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, BF, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, BF, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[9292] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, 2E, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, 2E, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, 2E, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, 2E, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, 2E, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[9368] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, 57, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, 57, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, 57, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, 57, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, 57, FF, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe[9444] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe[9472] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, F8, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe[9540] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, 06, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, 06, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, 06, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, 06, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, 06, 7F, 00, 00, 00, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[9656] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc7ae94b14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc7ae94f3c 8 bytes [60, 6E, CD, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc7ae95216 8 bytes [50, 6E, CD, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc7ae9540f 8 bytes {JMP 0xffffffffffffffee}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc7ae957af 8 bytes [30, 6E, CD, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc7ae95964 8 bytes [20, 6E, CD, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc7ae95f01 8 bytes {JMP 0xffffffffffffff9e}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc7ae95f5e 8 bytes [F0, 6D, CD, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc7af112a0 8 bytes {JMP QWORD [RIP-0x7baf7]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc7af11420 8 bytes {JMP QWORD [RIP-0x7bac2]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc7af11450 8 bytes {JMP QWORD [RIP-0x7c51a]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc7af11570 8 bytes {JMP QWORD [RIP-0x7c167]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc7af11620 8 bytes {JMP QWORD [RIP-0x7c410]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc7af11ce0 8 bytes {JMP QWORD [RIP-0x7bd88]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc7af11fe0 8 bytes {JMP QWORD [RIP-0x7c0e5]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc7af12860 8 bytes {JMP QWORD [RIP-0x7cbfe]}
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 438 00000000776613f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 387 0000000077661583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077661621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077661674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000776616d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 00000000776616e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[9812] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077661727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] |