Polarbär | 29.07.2012 14:35 | GMER 5.Teil Zitat:
.text C:\WINDOWS\system32\services.exe[1180] ADVAPI32.dll!LookupPrivilegeValueA 77DCC220 6 Bytes JMP 7099000A
.text C:\WINDOWS\system32\services.exe[1180] ADVAPI32.dll!LsaRemoveAccountRights 77DEAB91 6 Bytes JMP 7168000A
.text C:\WINDOWS\system32\services.exe[1180] ADVAPI32.dll!CreateServiceA 77E07359 6 Bytes JMP 7120000A
.text C:\WINDOWS\system32\services.exe[1180] ADVAPI32.dll!CreateServiceW 77E074F1 6 Bytes JMP 711D000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!SetWindowTextW 7E36BC36 6 Bytes JMP 7066000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 7132000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetWindowTextW 7E36CDB6 6 Bytes JMP 70C6000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!DrawTextW 7E36D7C2 6 Bytes JMP 707E000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!ShowWindow 7E36D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!ShowWindow + 4 7E36D8A8 2 Bytes [C2, 70]
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [2B, 71]
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 712F000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!CreateWindowExW 7E36FC25 6 Bytes JMP 7078000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!CreateWindowExA 7E36FF33 6 Bytes JMP 707B000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 7156000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!SetWindowTextA 7E37F52B 6 Bytes JMP 7069000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 7159000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!SetWinEventHook 7E3817B7 6 Bytes JMP 711A000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!GetWindowTextA 7E38212B 6 Bytes JMP 70C9000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!DrawTextA 7E38C6CA 6 Bytes JMP 7081000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!DdeConnect 7E3A7F93 6 Bytes JMP 7129000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!EndTask 7E3A9E75 6 Bytes JMP 713E000A
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!RegisterRawInputDevices 7E3BCBD4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[1180] USER32.dll!RegisterRawInputDevices + 4 7E3BCBD8 2 Bytes [16, 71]
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!ShellExecuteExW 7E6B25D3 6 Bytes JMP 7144000A
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!Shell_NotifyIcon 7E6D18BE 6 Bytes JMP 70B1000A
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!Shell_NotifyIconW 7E6D62A5 6 Bytes JMP 70AE000A
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!ShellExecuteEx 7E6F0E95 6 Bytes JMP 7147000A
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!ShellExecuteA 7E6F11C0 6 Bytes JMP 714D000A
.text C:\WINDOWS\system32\services.exe[1180] SHELL32.dll!ShellExecuteW 7E7659D0 6 Bytes JMP 714A000A
.text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!NtLoadDriver 7C91D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!NtLoadDriver + 4 7C91D472 2 Bytes [22, 71]
.text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!NtSuspendProcess 7C91DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!NtSuspendProcess + 4 7C91DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\system32\lsass.exe[1200] ntdll.dll!RtlDosSearchPath_U + 1D1 7C926ADA 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!DeviceIoControl 7C801629 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!DeviceIoControl + 4 7C80162D 2 Bytes [AA, 70]
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!VirtualAlloc 7C809AA1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!MultiByteToWideChar 7C809C48 6 Bytes JMP 7084000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!LoadResource 7C80A005 6 Bytes JMP 70C0000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!WideCharToMultiByte 7C80A124 6 Bytes JMP 7063000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!GetProcAddress 7C80ADF0 6 Bytes JMP 7114000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!LoadLibraryW 7C80AE9B 6 Bytes JMP 715C000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateMutexW 7C80E907 6 Bytes JMP 708D000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateMutexA 7C80E98F 6 Bytes JMP 7090000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!OpenMutexW 7C80E9E5 6 Bytes JMP 7087000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!OpenMutexA 7C80EA6B 6 Bytes JMP 708A000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!GetVolumeInformationW 7C80FA35 6 Bytes JMP 710E000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateRemoteThread 7C81047C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateRemoteThread + 4 7C810480 2 Bytes [6D, 71]
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateThread 7C810687 6 Bytes JMP 70D8000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateFileW 7C8107B0 6 Bytes JMP 70E1000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!WriteFile 7C810DD7 6 Bytes JMP 70A2000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!TerminateThread 7C81CAEB 6 Bytes JMP 7138000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!MoveFileW 7C821211 6 Bytes JMP 705D000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateDirectoryA 7C82175C 6 Bytes JMP 70A8000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!GetVolumeInformationA 7C821B55 6 Bytes JMP 7111000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CopyFileExW 7C827AE2 6 Bytes JMP 70B4000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CopyFileA 7C82869E 6 Bytes JMP 70BD000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CopyFileW 7C82F82B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!OpenProcess 7C830999 6 Bytes JMP 7054000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!DeleteFileA 7C831E8D 6 Bytes JMP 7075000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!DeleteFileW 7C831F13 6 Bytes JMP 7072000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateDirectoryW 7C8323B2 6 Bytes JMP 70A5000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!MoveFileExW 7C83563B 6 Bytes JMP 7057000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!MoveFileA 7C835E6F 6 Bytes JMP 7060000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!DebugActiveProcess 7C85AF93 6 Bytes JMP 7135000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!MoveFileExA 7C85E333 6 Bytes JMP 705A000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CopyFileExA 7C85F234 6 Bytes JMP 70B7000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!WinExec 7C8622B5 6 Bytes JMP 7141000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!SetThreadContext 7C8639B1 6 Bytes JMP 709F000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!CreateToolhelp32Snapshot 7C865A27 6 Bytes JMP 70DB000A
.text C:\WINDOWS\system32\lsass.exe[1200] kernel32.dll!GetBinaryTypeW + 80 7C868B34 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 6 Bytes JMP 70F6000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegQueryValueExW 77DA6FFF 6 Bytes JMP 70E4000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegCreateKeyExW 77DA776C 6 Bytes JMP 7108000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegOpenKeyExA 77DA7852 6 Bytes JMP 70F9000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegOpenKeyW 77DA7946 6 Bytes JMP 70FC000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!OpenProcessToken 77DA798B 6 Bytes JMP 709C000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegQueryValueExA 77DA7ABB 6 Bytes JMP 70E7000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegSetValueExW 77DAD747 6 Bytes JMP 70F0000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegQueryValueW 77DAD85A 6 Bytes JMP 70EA000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegCreateKeyExA 77DAE9D4 6 Bytes JMP 710B000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegSetValueExA 77DAEAC7 6 Bytes JMP 70F3000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegOpenKeyA 77DAEFA8 6 Bytes JMP 70FF000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!AdjustTokenPrivileges 77DAEFEC 6 Bytes JMP 7093000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegDeleteKeyA 77DB4288 6 Bytes JMP 706F000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegDeleteKeyW 77DB5583 6 Bytes JMP 706C000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!OpenSCManagerW 77DB6F3D 6 Bytes JMP 70CC000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!OpenSCManagerA 77DC6996 6 Bytes JMP 70CF000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!LookupPrivilegeValueW 77DCB8C7 6 Bytes JMP 7096000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegCreateKeyW 77DCBA3D 6 Bytes JMP 7102000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegQueryValueA 77DCBB75 4 Bytes JMP EC001E25
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegQueryValueA + 5 77DCBB7A 1 Byte [70]
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!RegCreateKeyA 77DCBCDB 6 Bytes JMP 7105000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!LookupPrivilegeValueA 77DCC220 6 Bytes JMP 7099000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!LsaRemoveAccountRights 77DEAB91 6 Bytes JMP 7168000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!CreateServiceA 77E07359 6 Bytes JMP 7120000A
.text C:\WINDOWS\system32\lsass.exe[1200] ADVAPI32.dll!CreateServiceW 77E074F1 6 Bytes JMP 711D000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!SetWindowTextW 7E36BC36 6 Bytes JMP 7066000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 7132000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetWindowTextW 7E36CDB6 6 Bytes JMP 70C6000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!DrawTextW 7E36D7C2 6 Bytes JMP 707E000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!ShowWindow 7E36D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!ShowWindow + 4 7E36D8A8 2 Bytes [C2, 70]
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [2B, 71]
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 712F000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!CreateWindowExW 7E36FC25 6 Bytes JMP 7078000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!CreateWindowExA 7E36FF33 6 Bytes JMP 707B000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 7156000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!SetWindowTextA 7E37F52B 6 Bytes JMP 7069000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 7159000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!SetWinEventHook 7E3817B7 6 Bytes JMP 711A000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!GetWindowTextA 7E38212B 6 Bytes JMP 70C9000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!DrawTextA 7E38C6CA 6 Bytes JMP 7081000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!DdeConnect 7E3A7F93 6 Bytes JMP 7129000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!EndTask 7E3A9E75 6 Bytes JMP 713E000A
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!RegisterRawInputDevices 7E3BCBD4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1200] USER32.dll!RegisterRawInputDevices + 4 7E3BCBD8 2 Bytes [16, 71]
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!ShellExecuteExW 7E6B25D3 6 Bytes JMP 7144000A
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!Shell_NotifyIcon 7E6D18BE 6 Bytes JMP 70B1000A
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!Shell_NotifyIconW 7E6D62A5 6 Bytes JMP 70AE000A
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!ShellExecuteEx 7E6F0E95 6 Bytes JMP 7147000A
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!ShellExecuteA 7E6F11C0 6 Bytes JMP 714D000A
.text C:\WINDOWS\system32\lsass.exe[1200] SHELL32.dll!ShellExecuteW 7E7659D0 6 Bytes JMP 714A000A
.text C:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtLoadDriver 7C91D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtLoadDriver + 4 7C91D472 2 Bytes [22, 71]
.text C:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtSuspendProcess 7C91DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtSuspendProcess + 4 7C91DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!RtlDosSearchPath_U + 1D1 7C926ADA 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!DeviceIoControl 7C801629 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!DeviceIoControl + 4 7C80162D 2 Bytes [AA, 70]
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!VirtualAlloc 7C809AA1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!MultiByteToWideChar 7C809C48 6 Bytes JMP 7084000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!LoadResource 7C80A005 6 Bytes JMP 70C0000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!WideCharToMultiByte 7C80A124 6 Bytes JMP 7063000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!GetProcAddress 7C80ADF0 6 Bytes JMP 7114000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!LoadLibraryW 7C80AE9B 6 Bytes JMP 715C000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateMutexW 7C80E907 6 Bytes JMP 708D000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateMutexA 7C80E98F 6 Bytes JMP 7090000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!OpenMutexW 7C80E9E5 6 Bytes JMP 7087000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!OpenMutexA 7C80EA6B 6 Bytes JMP 708A000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!GetVolumeInformationW 7C80FA35 6 Bytes JMP 710E000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateRemoteThread 7C81047C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateRemoteThread + 4 7C810480 2 Bytes [6D, 71]
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateThread 7C810687 6 Bytes JMP 70D8000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateFileW 7C8107B0 6 Bytes JMP 70E1000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!WriteFile 7C810DD7 6 Bytes JMP 70A2000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!TerminateThread 7C81CAEB 6 Bytes JMP 7138000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!MoveFileW 7C821211 6 Bytes JMP 705D000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateDirectoryA 7C82175C 6 Bytes JMP 70A8000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!GetVolumeInformationA 7C821B55 6 Bytes JMP 7111000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CopyFileExW 7C827AE2 6 Bytes JMP 70B4000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CopyFileA 7C82869E 6 Bytes JMP 70BD000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CopyFileW 7C82F82B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!OpenProcess 7C830999 6 Bytes JMP 7054000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!DeleteFileA 7C831E8D 6 Bytes JMP 7075000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!DeleteFileW 7C831F13 6 Bytes JMP 7072000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateDirectoryW 7C8323B2 6 Bytes JMP 70A5000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!MoveFileExW 7C83563B 6 Bytes JMP 7057000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!MoveFileA 7C835E6F 6 Bytes JMP 7060000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!DebugActiveProcess 7C85AF93 6 Bytes JMP 7135000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!MoveFileExA 7C85E333 6 Bytes JMP 705A000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CopyFileExA 7C85F234 6 Bytes JMP 70B7000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!WinExec 7C8622B5 6 Bytes JMP 7141000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!SetThreadContext 7C8639B1 6 Bytes JMP 709F000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!CreateToolhelp32Snapshot 7C865A27 6 Bytes JMP 70DB000A
.text C:\WINDOWS\System32\svchost.exe[1268] kernel32.dll!GetBinaryTypeW + 80 7C868B34 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 6 Bytes JMP 70F6000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegQueryValueExW 77DA6FFF 6 Bytes JMP 70E4000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExW 77DA776C 6 Bytes JMP 7108000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExA 77DA7852 6 Bytes JMP 70F9000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyW 77DA7946 6 Bytes JMP 70FC000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!OpenProcessToken 77DA798B 6 Bytes JMP 709C000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegQueryValueExA 77DA7ABB 6 Bytes JMP 70E7000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegSetValueExW 77DAD747 6 Bytes JMP 70F0000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegQueryValueW 77DAD85A 6 Bytes JMP 70EA000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExA 77DAE9D4 6 Bytes JMP 710B000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegSetValueExA 77DAEAC7 6 Bytes JMP 70F3000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyA 77DAEFA8 6 Bytes JMP 70FF000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!AdjustTokenPrivileges 77DAEFEC 6 Bytes JMP 7093000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegDeleteKeyA 77DB4288 6 Bytes JMP 706F000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegDeleteKeyW 77DB5583 6 Bytes JMP 706C000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!OpenSCManagerW 77DB6F3D 6 Bytes JMP 70CC000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!OpenSCManagerA 77DC6996 6 Bytes JMP 70CF000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!LookupPrivilegeValueW 77DCB8C7 6 Bytes JMP 7096000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyW 77DCBA3D 6 Bytes JMP 7102000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegQueryValueA 77DCBB75 4 Bytes JMP EC001E25
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegQueryValueA + 5 77DCBB7A 1 Byte [70]
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyA 77DCBCDB 6 Bytes JMP 7105000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!LookupPrivilegeValueA 77DCC220 6 Bytes JMP 7099000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!LsaRemoveAccountRights 77DEAB91 6 Bytes JMP 7168000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!CreateServiceA 77E07359 6 Bytes JMP 7120000A
.text C:\WINDOWS\System32\svchost.exe[1268] ADVAPI32.dll!CreateServiceW 77E074F1 6 Bytes JMP 711D000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!SetWindowTextW 7E36BC36 6 Bytes JMP 7066000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 7132000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetWindowTextW 7E36CDB6 6 Bytes JMP 70C6000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!DrawTextW 7E36D7C2 6 Bytes JMP 707E000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!ShowWindow 7E36D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!ShowWindow + 4 7E36D8A8 2 Bytes [C2, 70]
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [2B, 71]
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 712F000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!CreateWindowExW 7E36FC25 6 Bytes JMP 7078000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!CreateWindowExA 7E36FF33 6 Bytes JMP 707B000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 7156000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!SetWindowTextA 7E37F52B 6 Bytes JMP 7069000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 7159000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!SetWinEventHook 7E3817B7 6 Bytes JMP 711A000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!GetWindowTextA 7E38212B 6 Bytes JMP 70C9000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!DrawTextA 7E38C6CA 6 Bytes JMP 7081000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!DdeConnect 7E3A7F93 6 Bytes JMP 7129000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!EndTask 7E3A9E75 6 Bytes JMP 713E000A
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!RegisterRawInputDevices 7E3BCBD4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1268] USER32.dll!RegisterRawInputDevices + 4 7E3BCBD8 2 Bytes [16, 71]
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!ShellExecuteExW 7E6B25D3 6 Bytes JMP 7144000A
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!Shell_NotifyIcon 7E6D18BE 6 Bytes JMP 70B1000A
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!Shell_NotifyIconW 7E6D62A5 6 Bytes JMP 70AE000A
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!ShellExecuteEx 7E6F0E95 6 Bytes JMP 7147000A
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!ShellExecuteA 7E6F11C0 6 Bytes JMP 714D000A
.text C:\WINDOWS\System32\svchost.exe[1268] SHELL32.dll!ShellExecuteW 7E7659D0 6 Bytes JMP 714A000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ntdll.dll!NtLoadDriver 7C91D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ntdll.dll!NtLoadDriver + 4 7C91D472 2 Bytes [22, 71]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ntdll.dll!NtSuspendProcess 7C91DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ntdll.dll!NtSuspendProcess + 4 7C91DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ntdll.dll!RtlDosSearchPath_U + 1D1 7C926ADA 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!DeviceIoControl 7C801629 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!DeviceIoControl + 4 7C80162D 2 Bytes [AA, 70]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!VirtualAlloc 7C809AA1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!MultiByteToWideChar 7C809C48 6 Bytes JMP 7084000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!LoadResource 7C80A005 6 Bytes JMP 70C0000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!WideCharToMultiByte 7C80A124 6 Bytes JMP 7063000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!GetProcAddress 7C80ADF0 6 Bytes JMP 7114000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!LoadLibraryW 7C80AE9B 6 Bytes JMP 715C000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateMutexW 7C80E907 6 Bytes JMP 708D000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateMutexA 7C80E98F 6 Bytes JMP 7090000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!OpenMutexW 7C80E9E5 6 Bytes JMP 7087000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!OpenMutexA 7C80EA6B 6 Bytes JMP 708A000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!GetVolumeInformationW 7C80FA35 6 Bytes JMP 710E000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateRemoteThread 7C81047C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateRemoteThread + 4 7C810480 2 Bytes [6D, 71]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateThread 7C810687 6 Bytes JMP 70D8000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateFileW 7C8107B0 6 Bytes JMP 70E1000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!WriteFile 7C810DD7 6 Bytes JMP 70A2000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!TerminateThread 7C81CAEB 6 Bytes JMP 7138000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!MoveFileW 7C821211 6 Bytes JMP 705D000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateDirectoryA 7C82175C 6 Bytes JMP 70A8000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!GetVolumeInformationA 7C821B55 6 Bytes JMP 7111000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CopyFileExW 7C827AE2 6 Bytes JMP 70B4000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CopyFileA 7C82869E 6 Bytes JMP 70BD000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CopyFileW 7C82F82B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!OpenProcess 7C830999 6 Bytes JMP 7054000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!DeleteFileA 7C831E8D 6 Bytes JMP 7075000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!DeleteFileW 7C831F13 6 Bytes JMP 7072000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateDirectoryW 7C8323B2 6 Bytes JMP 70A5000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!MoveFileExW 7C83563B 6 Bytes JMP 7057000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!MoveFileA 7C835E6F 6 Bytes JMP 7060000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!DebugActiveProcess 7C85AF93 6 Bytes JMP 7135000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!MoveFileExA 7C85E333 6 Bytes JMP 705A000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CopyFileExA 7C85F234 6 Bytes JMP 70B7000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!WinExec 7C8622B5 6 Bytes JMP 7141000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!SetThreadContext 7C8639B1 6 Bytes JMP 709F000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!CreateToolhelp32Snapshot 7C865A27 6 Bytes JMP 70DB000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] kernel32.dll!GetBinaryTypeW + 80 7C868B34 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!SetWindowTextW 7E36BC36 6 Bytes JMP 7066000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 7132000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetWindowTextW 7E36CDB6 6 Bytes JMP 70C6000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!DrawTextW 7E36D7C2 6 Bytes JMP 707E000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!ShowWindow 7E36D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!ShowWindow + 4 7E36D8A8 2 Bytes [C2, 70]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [2B, 71]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 712F000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!CreateWindowExW 7E36FC25 6 Bytes JMP 7078000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!CreateWindowExA 7E36FF33 6 Bytes JMP 707B000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 7156000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!SetWindowTextA 7E37F52B 6 Bytes JMP 7069000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 7159000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!SetWinEventHook 7E3817B7 6 Bytes JMP 711A000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!GetWindowTextA 7E38212B 6 Bytes JMP 70C9000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!DrawTextA 7E38C6CA 6 Bytes JMP 7081000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!DdeConnect 7E3A7F93 6 Bytes JMP 7129000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!EndTask 7E3A9E75 6 Bytes JMP 713E000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!RegisterRawInputDevices 7E3BCBD4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] USER32.dll!RegisterRawInputDevices + 4 7E3BCBD8 2 Bytes [16, 71]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 6 Bytes JMP 70F6000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegQueryValueExW 77DA6FFF 6 Bytes JMP 70E4000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegCreateKeyExW 77DA776C 6 Bytes JMP 7108000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegOpenKeyExA 77DA7852 6 Bytes JMP 70F9000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegOpenKeyW 77DA7946 6 Bytes JMP 70FC000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!OpenProcessToken 77DA798B 6 Bytes JMP 709C000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegQueryValueExA 77DA7ABB 6 Bytes JMP 70E7000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegSetValueExW 77DAD747 6 Bytes JMP 70F0000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegQueryValueW 77DAD85A 6 Bytes JMP 70EA000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegCreateKeyExA 77DAE9D4 6 Bytes JMP 710B000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegSetValueExA 77DAEAC7 6 Bytes JMP 70F3000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegOpenKeyA 77DAEFA8 6 Bytes JMP 70FF000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!AdjustTokenPrivileges 77DAEFEC 6 Bytes JMP 7093000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegDeleteKeyA 77DB4288 6 Bytes JMP 706F000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegDeleteKeyW 77DB5583 6 Bytes JMP 706C000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!OpenSCManagerW 77DB6F3D 6 Bytes JMP 70CC000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!OpenSCManagerA 77DC6996 6 Bytes JMP 70CF000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!LookupPrivilegeValueW 77DCB8C7 6 Bytes JMP 7096000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegCreateKeyW 77DCBA3D 6 Bytes JMP 7102000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegQueryValueA 77DCBB75 4 Bytes JMP EC001E25
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegQueryValueA + 5 77DCBB7A 1 Byte [70]
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!RegCreateKeyA 77DCBCDB 6 Bytes JMP 7105000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!LookupPrivilegeValueA 77DCC220 6 Bytes JMP 7099000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!LsaRemoveAccountRights 77DEAB91 6 Bytes JMP 7168000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!CreateServiceA 77E07359 6 Bytes JMP 7120000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] ADVAPI32.dll!CreateServiceW 77E074F1 6 Bytes JMP 711D000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!ShellExecuteExW 7E6B25D3 6 Bytes JMP 7144000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!Shell_NotifyIcon 7E6D18BE 6 Bytes JMP 70B1000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!Shell_NotifyIconW 7E6D62A5 6 Bytes JMP 70AE000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!ShellExecuteEx 7E6F0E95 6 Bytes JMP 7147000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!ShellExecuteA 7E6F11C0 6 Bytes JMP 714D000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1380] SHELL32.dll!ShellExecuteW 7E7659D0 6 Bytes JMP 714A000A
.text C:\WINDOWS\system32\svchost.exe[1400] ntdll.dll!NtLoadDriver 7C91D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] ntdll.dll!NtLoadDriver + 4 7C91D472 2 Bytes [22, 71]
.text C:\WINDOWS\system32\svchost.exe[1400] ntdll.dll!NtSuspendProcess 7C91DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] ntdll.dll!NtSuspendProcess + 4 7C91DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\system32\svchost.exe[1400] ntdll.dll!RtlDosSearchPath_U + 1D1 7C926ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!DeviceIoControl 7C801629 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!DeviceIoControl + 4 7C80162D 2 Bytes [AA, 70]
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!VirtualAlloc 7C809AA1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!MultiByteToWideChar 7C809C48 6 Bytes JMP 7084000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadResource 7C80A005 6 Bytes JMP 70C0000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!WideCharToMultiByte 7C80A124 6 Bytes JMP 7063000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetProcAddress 7C80ADF0 6 Bytes JMP 7114000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW 7C80AE9B 6 Bytes JMP 715C000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateMutexW 7C80E907 6 Bytes JMP 708D000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateMutexA 7C80E98F 6 Bytes JMP 7090000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!OpenMutexW 7C80E9E5 6 Bytes JMP 7087000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!OpenMutexA 7C80EA6B 6 Bytes JMP 708A000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetVolumeInformationW 7C80FA35 6 Bytes JMP 710E000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateRemoteThread 7C81047C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateRemoteThread + 4 7C810480 2 Bytes [6D, 71]
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateThread 7C810687 6 Bytes JMP 70D8000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateFileW 7C8107B0 6 Bytes JMP 70E1000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!WriteFile 7C810DD7 6 Bytes JMP 70A2000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!TerminateThread 7C81CAEB 6 Bytes JMP 7138000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!MoveFileW 7C821211 6 Bytes JMP 705D000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateDirectoryA 7C82175C 6 Bytes JMP 70A8000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetVolumeInformationA 7C821B55 6 Bytes JMP 7111000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CopyFileExW 7C827AE2 6 Bytes JMP 70B4000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CopyFileA 7C82869E 6 Bytes JMP 70BD000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CopyFileW 7C82F82B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!OpenProcess 7C830999 6 Bytes JMP 7054000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!DeleteFileA 7C831E8D 6 Bytes JMP 7075000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!DeleteFileW 7C831F13 6 Bytes JMP 7072000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateDirectoryW 7C8323B2 6 Bytes JMP 70A5000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!MoveFileExW 7C83563B 6 Bytes JMP 7057000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!MoveFileA 7C835E6F 6 Bytes JMP 7060000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!DebugActiveProcess 7C85AF93 6 Bytes JMP 7135000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!MoveFileExA 7C85E333 6 Bytes JMP 705A000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CopyFileExA 7C85F234 6 Bytes JMP 70B7000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!WinExec 7C8622B5 6 Bytes JMP 7141000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!SetThreadContext 7C8639B1 6 Bytes JMP 709F000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!CreateToolhelp32Snapshot 7C865A27 6 Bytes JMP 70DB000A
.text C:\WINDOWS\system32\svchost.exe[1400] kernel32.dll!GetBinaryTypeW + 80 7C868B34 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 6 Bytes JMP 70F6000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegQueryValueExW 77DA6FFF 6 Bytes JMP 70E4000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 77DA776C 6 Bytes JMP 7108000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 77DA7852 6 Bytes JMP 70F9000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 77DA7946 6 Bytes JMP 70FC000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!OpenProcessToken 77DA798B 6 Bytes JMP 709C000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegQueryValueExA 77DA7ABB 6 Bytes JMP 70E7000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegSetValueExW 77DAD747 6 Bytes JMP 70F0000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegQueryValueW 77DAD85A 6 Bytes JMP 70EA000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 77DAE9D4 6 Bytes JMP 710B000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegSetValueExA 77DAEAC7 6 Bytes JMP 70F3000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 77DAEFA8 6 Bytes JMP 70FF000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!AdjustTokenPrivileges 77DAEFEC 6 Bytes JMP 7093000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegDeleteKeyA 77DB4288 6 Bytes JMP 706F000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegDeleteKeyW 77DB5583 6 Bytes JMP 706C000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!OpenSCManagerW 77DB6F3D 6 Bytes JMP 70CC000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!OpenSCManagerA 77DC6996 6 Bytes JMP 70CF000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!LookupPrivilegeValueW 77DCB8C7 6 Bytes JMP 7096000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 77DCBA3D 6 Bytes JMP 7102000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegQueryValueA 77DCBB75 4 Bytes JMP EC001E25
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegQueryValueA + 5 77DCBB7A 1 Byte [70]
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 77DCBCDB 6 Bytes JMP 7105000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!LookupPrivilegeValueA 77DCC220 6 Bytes JMP 7099000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!LsaRemoveAccountRights 77DEAB91 6 Bytes JMP 7168000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!CreateServiceA 77E07359 6 Bytes JMP 7120000A
.text C:\WINDOWS\system32\svchost.exe[1400] ADVAPI32.dll!CreateServiceW 77E074F1 6 Bytes JMP 711D000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!SetWindowTextW 7E36BC36 6 Bytes JMP 7066000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 7132000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetWindowTextW 7E36CDB6 6 Bytes JMP 70C6000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!DrawTextW 7E36D7C2 6 Bytes JMP 707E000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!ShowWindow 7E36D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!ShowWindow + 4 7E36D8A8 2 Bytes [C2, 70]
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [2B, 71]
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 712F000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!CreateWindowExW 7E36FC25 6 Bytes JMP 7078000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!CreateWindowExA 7E36FF33 6 Bytes JMP 707B000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 7156000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!SetWindowTextA 7E37F52B 6 Bytes JMP 7069000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 7159000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!SetWinEventHook 7E3817B7 6 Bytes JMP 711A000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!GetWindowTextA 7E38212B 6 Bytes JMP 70C9000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!DrawTextA 7E38C6CA 6 Bytes JMP 7081000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!DdeConnect 7E3A7F93 6 Bytes JMP 7129000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!EndTask 7E3A9E75 6 Bytes JMP 713E000A
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!RegisterRawInputDevices 7E3BCBD4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1400] USER32.dll!RegisterRawInputDevices + 4 7E3BCBD8 2 Bytes [16, 71]
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!ShellExecuteExW 7E6B25D3 6 Bytes JMP 7144000A
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!Shell_NotifyIcon 7E6D18BE 6 Bytes JMP 70B1000A
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!Shell_NotifyIconW 7E6D62A5 6 Bytes JMP 70AE000A
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!ShellExecuteEx 7E6F0E95 6 Bytes JMP 7147000A
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!ShellExecuteA 7E6F11C0 6 Bytes JMP 714D000A
.text C:\WINDOWS\system32\svchost.exe[1400] SHELL32.dll!ShellExecuteW 7E7659D0 6 Bytes JMP 714A000A
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtLoadDriver 7C91D46E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtLoadDriver + 4 7C91D472 2 Bytes [22, 71]
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtSuspendProcess 7C91DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!NtSuspendProcess + 4 7C91DE32 2 Bytes [3A, 71]
.text C:\WINDOWS\system32\svchost.exe[1472] ntdll.dll!RtlDosSearchPath_U + 1D1 7C926ADA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!DeviceIoControl 7C801629 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!DeviceIoControl + 4 7C80162D 2 Bytes [AA, 70]
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileA 7C801A28 6 Bytes JMP 70DE000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtectEx 7C801A61 6 Bytes JMP 7126000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualProtect 7C801AD4 6 Bytes JMP 70D2000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 716B000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 715F000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!TerminateProcess 7C801E1A 6 Bytes JMP 7165000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!WriteProcessMemory 7C802213 6 Bytes JMP 7162000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7150000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7153000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!VirtualAlloc 7C809AA1 6 Bytes JMP 70D5000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!MultiByteToWideChar 7C809C48 6 Bytes JMP 7084000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadResource 7C80A005 6 Bytes JMP 70C0000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!WideCharToMultiByte 7C80A124 6 Bytes JMP 7063000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetProcAddress 7C80ADF0 6 Bytes JMP 7114000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!LoadLibraryW 7C80AE9B 6 Bytes JMP 715C000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateMutexW 7C80E907 6 Bytes JMP 708D000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateMutexA 7C80E98F 6 Bytes JMP 7090000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!OpenMutexW 7C80E9E5 6 Bytes JMP 7087000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!OpenMutexA 7C80EA6B 6 Bytes JMP 708A000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetVolumeInformationW 7C80FA35 6 Bytes JMP 710E000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateRemoteThread 7C81047C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateRemoteThread + 4 7C810480 2 Bytes [6D, 71]
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateThread 7C810687 6 Bytes JMP 70D8000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateFileW 7C8107B0 6 Bytes JMP 70E1000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!WriteFile 7C810DD7 6 Bytes JMP 70A2000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!TerminateThread 7C81CAEB 6 Bytes JMP 7138000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!MoveFileW 7C821211 6 Bytes JMP 705D000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CreateDirectoryA 7C82175C 6 Bytes JMP 70A8000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!GetVolumeInformationA 7C821B55 6 Bytes JMP 7111000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CopyFileExW 7C827AE2 6 Bytes JMP 70B4000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CopyFileA 7C82869E 6 Bytes JMP 70BD000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!CopyFileW 7C82F82B 6 Bytes JMP 70BA000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!OpenProcess 7C830999 6 Bytes JMP 7054000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!DeleteFileA 7C831E8D 6 Bytes JMP 7075000A
.text C:\WINDOWS\system32\svchost.exe[1472] kernel32.dll!DeleteFileW 7C831F13 6 Bytes JMP 7072000A
.text
| |