Pappa Bear | 08.02.2015 12:07 | -2- Code:
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 91]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7B]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 89]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 85]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8B]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6B]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 83]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 73]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 75]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 87]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 95]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 67]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 65]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 7D]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 6D]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 69]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 71]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 6F]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 8D]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 93]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 7F]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 8F]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x81d150]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x77d0b0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x79d020]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 20]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x269770]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 24]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb0ee80]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xaeee30]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xa6ee20]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa4ee10]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb2eb90]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb4eb40]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xb8e400]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xace3e0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x8ed720]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8acb60]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x96bf10]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xbcb1c0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x92ae00]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xa89960]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8896c0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9a742c]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x86611c]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8057d0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x7c38a0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 84]
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0x9e1cf0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes JMP 4a4a4a4a
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xaa13dc]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x81de1c]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x8fd620]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xb9c600]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8b9f08]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa00ab0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb3c950]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x919e80]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x999b50]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7763d0]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xbc52c4]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7926b8]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9839f8]}
.text C:\Windows\system32\nvvsvc.exe[984] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9030ac]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 91]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7B]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 89]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 85]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8B]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6B]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 83]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 73]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 75]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 87]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 95]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 67]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 65]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 7D]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 6D]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 69]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 71]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 6F]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 8D]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 93]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 7F]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 8F]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x81d150]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x77d0b0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x79d020]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 10]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x219770]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 1F]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb0ee80]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xaeee30]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xa6ee20]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa4ee10]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb2eb90]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb4eb40]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xb8e400]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xace3e0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x8ed720]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8acb60]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x96bf10]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xbcb1c0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x92ae00]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xa89960]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8896c0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9a742c]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x86611c]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8057d0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x7c38a0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 84]
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0x9e1cf0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes {JMP QWORD [RIP+0xbe1b50]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xaa13dc]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x81de1c]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x8fd620]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xb9c600]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8b9f08]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa00ab0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb3c950]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x919e80]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x999b50]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7763d0]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xbc52c4]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7926b8]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9839f8]}
.text C:\WINDOWS\system32\svchost.exe[292] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9030ac]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 91]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7B]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 89]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 85]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8B]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6B]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 83]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 73]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 75]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 87]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 95]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 67]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 65]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 7D]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 6D]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 69]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 71]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 6F]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 8D]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 93]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 7F]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 8F]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x81d150]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x77d0b0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x79d020]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 10]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x219770]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 1F]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb0ee80]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xaeee30]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xa6ee20]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa4ee10]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb2eb90]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb4eb40]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xb8e400]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xace3e0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x8ed720]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8acb60]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x96bf10]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xbcb1c0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x92ae00]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xa89960]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8896c0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9a742c]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x86611c]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8057d0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x7c38a0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 84]
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0x9e1cf0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes {JMP QWORD [RIP+0xbe1b50]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xaa13dc]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x81de1c]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x8fd620]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xb9c600]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8b9f08]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa00ab0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb3c950]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x919e80]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x999b50]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7763d0]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xbc52c4]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7926b8]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9839f8]}
.text C:\WINDOWS\System32\svchost.exe[440] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9030ac]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 95]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7F]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 8D]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 89]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8F]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6F]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 87]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 77]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 79]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 8B]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 99]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 6B]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 69]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 81]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 71]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 6D]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 75]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 73]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 91]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 97]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 83]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 93]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x85d150]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x7bd0b0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x7dd020]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 10]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x219770]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 1F]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIf3 00007ff91f20f980 6 bytes {JMP QWORD [RIP+0x3706b0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIfEx 00007ff91f2402a4 6 bytes {JMP QWORD [RIP+0x31fd8c]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb4ee80]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xb2ee30]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xaaee20]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa8ee10]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb6eb90]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb8eb40]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xbce400]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xb0e3e0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x92d720]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8ecb60]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x9abf10]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xc0b1c0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x96ae00]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xac9960]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8c96c0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9e742c]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x8a611c]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8457d0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x8038a0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 88]
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0xa21cf0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes {JMP QWORD [RIP+0xc21b50]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xae13dc]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x85de1c]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x93d620]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xbdc600]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8f9f08]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa40ab0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb7c950]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x959e80]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x9d9b50]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7b63d0]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xc052c4]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7d26b8]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9c39f8]}
.text C:\WINDOWS\system32\svchost.exe[616] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9430ac]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 91]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7B]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 89]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 85]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8B]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6B]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 83]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 73]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 75]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 87]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 95]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 67]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 65]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 7D]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 6D]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 69]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 71]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 6F]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 8D]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 93]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 7F]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 8F]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x81d150]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x77d0b0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x79d020]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 10]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x219770]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 1F]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb0ee80]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xaeee30]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xa6ee20]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa4ee10]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb2eb90]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb4eb40]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xb8e400]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xace3e0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x8ed720]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8acb60]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x96bf10]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xbcb1c0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x92ae00]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xa89960]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8896c0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9a742c]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x86611c]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8057d0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x7c38a0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 84]
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0x9e1cf0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes {JMP QWORD [RIP+0xbe1b50]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xaa13dc]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x81de1c]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x8fd620]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xb9c600]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8b9f08]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa00ab0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb3c950]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x919e80]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x999b50]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7763d0]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xbc52c4]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7926b8]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9839f8]}
.text C:\WINDOWS\system32\svchost.exe[400] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9030ac]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!LdrUnloadDll 00007ff91f371838 6 bytes {JMP QWORD [RIP+0x1de7f8]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtClose 00007ff91f3e1760 5 bytes [FF, 25, D0, E8, 14]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetInformationProcess 00007ff91f3e1830 5 bytes [FF, 25, 00, E8, 91]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateProcess 00007ff91f3e1930 5 bytes [FF, 25, 00, E7, 7B]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenFile 00007ff91f3e19a0 5 bytes [FF, 25, 90, E6, 89]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtOpenSection 00007ff91f3e19e0 5 bytes [FF, 25, 50, E6, 85]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 00007ff91f3e1a80 5 bytes [FF, 25, B0, E5, 8B]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEvent 00007ff91f3e1af0 5 bytes [FF, 25, 40, E5, 6B]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSection 00007ff91f3e1b10 5 bytes [FF, 25, 20, E5, 83]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThread 00007ff91f3e1b50 5 bytes [FF, 25, E0, E4, 73]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtTerminateThread 00007ff91f3e1ba0 5 bytes [FF, 25, 90, E4, 75]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateFile 00007ff91f3e1bc0 5 bytes [FF, 25, 70, E4, 87]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcConnectPort 00007ff91f3e1dd0 5 bytes [FF, 25, 60, E2, 95]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcCreatePort 00007ff91f3e1df0 5 bytes [FF, 25, 40, E2, 67]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 00007ff91f3e1ef0 5 bytes [FF, 25, 40, E1, 65]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtConnectPort 00007ff91f3e1ff0 5 bytes [FF, 25, 40, E0, 7D]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateEventPair 00007ff91f3e2040 5 bytes [FF, 25, F0, DF, 6D]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateMutant 00007ff91f3e20d0 5 bytes [FF, 25, 60, DF, 69]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreatePort 00007ff91f3e2100 5 bytes [FF, 25, 30, DF, 71]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSemaphore 00007ff91f3e2160 5 bytes [FF, 25, D0, DE, 6F]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject 00007ff91f3e2170 5 bytes [FF, 25, C0, DE, 8D]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ff91f3e2180 5 bytes [FF, 25, B0, DE, 93]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtLoadDriver 00007ff91f3e2590 5 bytes [FF, 25, A0, DA, 7F]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtMakeTemporaryObject 00007ff91f3e2620 5 bytes [FF, 25, 10, DA, 8F]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSetSystemInformation 00007ff91f3e2ee0 6 bytes {JMP QWORD [RIP+0x81d150]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtShutdownSystem 00007ff91f3e2f80 6 bytes {JMP QWORD [RIP+0x77d0b0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\SYSTEM32\ntdll.dll!NtSystemDebugControl 00007ff91f3e3010 6 bytes {JMP QWORD [RIP+0x79d020]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff91ca75676 3 bytes [94, A9, 20]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff91ca868c0 6 bytes {JMP QWORD [RIP+0x269770]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff91ca8f8b0 5 bytes [FF, 25, 80, 07, 24]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff91ee011b0 6 bytes {JMP QWORD [RIP+0xb0ee80]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff91ee01200 6 bytes {JMP QWORD [RIP+0xaeee30]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff91ee01210 6 bytes {JMP QWORD [RIP+0xa6ee20]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff91ee01220 6 bytes {JMP QWORD [RIP+0xa4ee10]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff91ee014a0 6 bytes {JMP QWORD [RIP+0xb2eb90]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff91ee014f0 6 bytes {JMP QWORD [RIP+0xb4eb40]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff91ee01c30 6 bytes {JMP QWORD [RIP+0xb8e400]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff91ee01c50 6 bytes {JMP QWORD [RIP+0xace3e0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff91ee02910 6 bytes {JMP QWORD [RIP+0x8ed720]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff91ee034d0 6 bytes {JMP QWORD [RIP+0x8acb60]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff91ee04121 5 bytes {JMP QWORD [RIP+0x96bf10]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff91ee04e70 6 bytes {JMP QWORD [RIP+0xbcb1c0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff91ee05230 6 bytes {JMP QWORD [RIP+0x92ae00]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff91ee066d1 5 bytes {JMP QWORD [RIP+0xa89960]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff91ee06970 6 bytes {JMP QWORD [RIP+0x8896c0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff91ee08c04 6 bytes {JMP QWORD [RIP+0x9a742c]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff91ee09f14 6 bytes {JMP QWORD [RIP+0x86611c]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff91ee0a860 6 bytes {JMP QWORD [RIP+0x8057d0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff91ee0c790 6 bytes {JMP QWORD [RIP+0x7c38a0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff91ee0d938 5 bytes [FF, 25, F8, 26, 84]
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff91ee0e340 6 bytes {JMP QWORD [RIP+0x9e1cf0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff91ee0e4e0 6 bytes {JMP QWORD [RIP+0xbe1b50]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff91ee0ec54 6 bytes {JMP QWORD [RIP+0xaa13dc]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff91ee12215 5 bytes {JMP QWORD [RIP+0x81de1c]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff91ee12a10 6 bytes {JMP QWORD [RIP+0x8fd620]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff91ee13a30 6 bytes {JMP QWORD [RIP+0xb9c600]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff91ee16128 6 bytes {JMP QWORD [RIP+0x8b9f08]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff91ee2f580 6 bytes {JMP QWORD [RIP+0xa00ab0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff91ee336e0 6 bytes {JMP QWORD [RIP+0xb3c950]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff91ee361b0 6 bytes {JMP QWORD [RIP+0x919e80]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff91ee364e0 6 bytes {JMP QWORD [RIP+0x999b50]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff91ee39c60 6 bytes {JMP QWORD [RIP+0x7763d0]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff91ee4ad6c 6 bytes {JMP QWORD [RIP+0xbc52c4]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff91ee5d978 6 bytes {JMP QWORD [RIP+0x7926b8]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff91ee8c638 6 bytes {JMP QWORD [RIP+0x9839f8]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff91ee8cf84 6 bytes {JMP QWORD [RIP+0x9030ac]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!BitBlt 00007ff91efe3bb0 6 bytes {JMP QWORD [RIP+0x1fc480]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!CreateDCA 00007ff91eff2eec 6 bytes {JMP QWORD [RIP+0x15d144]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!CreateDCW 00007ff91eff30d0 6 bytes {JMP QWORD [RIP+0x17cf60]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!StretchBlt 00007ff91effe77c 6 bytes {JMP QWORD [RIP+0x5918b4]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!GetPixel 00007ff91effe8e0 6 bytes {JMP QWORD [RIP+0x191750]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!MaskBlt 00007ff91f006598 6 bytes {JMP QWORD [RIP+0x4f9a98]}
.text C:\WINDOWS\system32\igfxCUIService.exe[1036] C:\WINDOWS\system32\GDI32.dll!PlgBlt 00007ff91f053514 6 bytes {JMP QWORD [RIP+0x51cb1c]} |