GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-06-27 20:08:13 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST1000DM003-1CH162 rev.CC44 931,51GB Running: hb66q2y8.exe; Driver: C:\Users\UKASZ~1\AppData\Local\Temp\pgldqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 93, 7F, 00, 00, 00, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files\Tablet\Pen\WacomHost.exe[3912] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 93, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[4700] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 0C, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4240] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[4884] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, F8, 7F, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2536] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 20, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1980] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 8C, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5808] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, A2, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5944] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, CE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2464] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, A7, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3712] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, C9, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3356] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, A2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5904] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 1B, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5936] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 37, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3300] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, A8, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4644] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, B8, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2276] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, 40, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes {JO 0x6e; JMP 0x2} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes {INS BYTE [RDI], DX; JMP 0x2} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, EB, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, EB, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, EB, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, EB, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2112] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, EB, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlPrefixString + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocIoCompletion + 710 00007ffc980a5206 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitForWnfMetaNotification + 479 00007ffc980a53ff 8 bytes {JMP 0xffffffffffffffee} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUserThreadStart + 911 00007ffc980a579f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWork + 420 00007ffc980a5954 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWaitOnAddress + 657 00007ffc980a5ef1 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfNotificationWaitForCompletion + 78 00007ffc980a5f4e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlWakeAddressAll + 399 00007ffc980a60ef 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlUnsubscribeWnfStateChangeNotification + 977 00007ffc980a64d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 310 00007ffc980a6616 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSimpleTryPost + 491 00007ffc980a66cb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlReportSilentProcessExit + 359 00007ffc980a8397 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 67 00007ffc980a8a13 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrFindEntryForAddress + 864 00007ffc980a8d30 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrGetDllHandleByName + 143 00007ffc980a8e9f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 510 00007ffc980a90ae 8 bytes {JMP 0xffffffffffffff96} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrInitializeThunk + 715 00007ffc980a917b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlQueueWorkItem + 772 00007ffc980a9d14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrAddRefDll + 685 00007ffc980a9fcd 8 bytes {JMP 0xffffffffffffffaf} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 352 00007ffc980aaae0 8 bytes {JMP 0xffffffffffffffcd} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!SbSelectProcedure + 488 00007ffc980aab68 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetVersion + 565 00007ffc980ab2e5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlGetNtProductType + 78 00007ffc980ab33e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 311 00007ffc980ac4d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll + 528 00007ffc980ac5b0 8 bytes {JMP 0xffffffffffffffc7} .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 579 00007ffc980ad0d3 8 bytes {JMP 0xffffffffffffffef} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlFreeThreadActivationContextStack + 47 00007ffc980ad10f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProcessFlsData + 495 00007ffc980ad57f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 43 00007ffc980ad6eb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDetectHeapLeaks + 456 00007ffc980ad888 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpReleaseWait + 180 00007ffc980ad944 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffc980adba4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpAllocWait + 424 00007ffc980add58 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 771 00007ffc980ae073 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!TpSetWaitEx + 948 00007ffc980ae124 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffc980ae160 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRandomEx + 756 00007ffc980aeb74 8 bytes {JMP 0xffffffffffffffd0} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDeleteFunctionTable + 371 00007ffc980afe63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlAddFunctionTable + 556 00007ffc980b009c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlProtectHeap + 171 00007ffc980b015b 8 bytes [70, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 744 00007ffc980b1438 8 bytes [40, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsW + 214 00007ffc980b15e6 8 bytes [30, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!EtwNotificationRegister + 567 00007ffc980b1877 8 bytes [20, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 429 00007ffc980b1a2d 8 bytes [10, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!RtlRunOnceExecuteOnce + 213 00007ffc980b1c35 8 bytes [00, 6C, E3, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffc98121290 8 bytes {JMP QWORD [RIP-0x6fe5e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffc98121410 8 bytes {JMP QWORD [RIP-0x6fe30]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffc98121440 8 bytes {JMP QWORD [RIP-0x712eb]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffc98121560 8 bytes {JMP QWORD [RIP-0x70c1e]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffc98121610 8 bytes {JMP QWORD [RIP-0x71122]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffc98121cd0 8 bytes {JMP QWORD [RIP-0x700a1]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffc98121fd0 8 bytes {JMP QWORD [RIP-0x705a9]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffc98122850 8 bytes {JMP QWORD [RIP-0x70fdf]} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuSetContext + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuGetContext + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077c41621 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077c41674 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077c416d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 9 0000000077c416e9 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuNotifyAffinityChange + 71 0000000077c41727 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 7 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077c425d0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077c42714 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuResetToConsistentState + 529 0000000077c42961 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5528] C:\WINDOWS\system32\wow64cpu.dll!CpuProcessTerm + 595 0000000077c42bd3 8 bytes [DC, 6A, E3, FE, 00, 00, 00, ...] .text + 132 00007ffc980a4b04 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text + 316 00007ffc980a4f2c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text + 438 0000000077c413f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text + 387 0000000077c41583 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\Explorer.EXE[3752] @ C:\WINDOWS\system32\RPCRT4.dll[ntdll.dll!NtAlpcConnectPortEx] [50544350] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\x64\prremote.dll ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [752:776] fffff960009a42d0 ---- Processes - GMER 2.1 ---- Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\python27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (Python Core/Python Software Foundation)(2015-06-27 17:54:20) 000000001e000000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32api.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001e8c0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\pywintypes27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 000000001e7a0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\pythoncom27.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000001ef0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_socket.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000000320000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_ssl.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000010000000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32com.shell.shell.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001e800000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_hashlib.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000002af0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._core_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000002e90000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxbase294u_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 0000000002fc0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxbase294u_net_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 0000000000370000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxmsw294u_core_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 00000000031b0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxmsw294u_adv_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 0000000003650000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._gdi_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000003790000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._windows_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000004060000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxmsw294u_html_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 0000000004130000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._controls_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 00000000043f0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._misc_.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000004500000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\pysqlite2._sqlite.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 00000000045c0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_ctypes.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 000000001d1a0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32file.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ea10000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32security.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ec80000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\hashobjs_ext.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000001f80000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\usb_ext.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000001f90000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32gui.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ea40000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32event.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001e9b0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_elementtree.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 000000001d100000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\pyexpat.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 00000000026b0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\common.time34.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 00000000041d0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_psutil_windows.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 00000000041e0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32inet.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001eaa0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32crypt.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001e980000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._html2.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000004200000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wxmsw294u_webview_vc90.dll (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884] (wxWidgets for MSW/wxWidgets development team)(2015-06-27 17:54:21) 0000000004230000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_multiprocessing.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000004250000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\_yappi.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000005640000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32process.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ebf0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\unicodedata.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 00000000056c0000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._wizard.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000005650000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32pipe.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001eb90000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\select.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:20) 0000000005690000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32pdh.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001eb60000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32profile.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ec20000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\win32ts.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 000000001ed40000 Library C:\Users\UKASZ~1\AppData\Local\Temp\_MEI42402\wx._animate.pyd (*** suspicious ***) @ C:\Program Files (x86)\Google\Drive\googledrivesync.exe [4884](2015-06-27 17:54:21) 0000000005790000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----