GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-06-21 08:32:44
Windows 6.0.6000
---- User code sections - GMER 1.0.14 ----
.text C:\Users\Administrator\Desktop\HijackThis\gmer\gmer.exe[700] ntdll.dll!NtCreateFile + 3 771AF417 2 Bytes JMP 0300BAFA
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!DialogBoxIndirectParamW 772F14DA 5 Bytes JMP 7193FEBF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!MessageBoxExA 7730570D 5 Bytes JMP 7193FE06 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!DialogBoxParamA 773065BF 5 Bytes JMP 7193FE84 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!MessageBoxIndirectW 7730F1B3 5 Bytes JMP 717D15DA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!DialogBoxParamW 7731129F 5 Bytes JMP 717AF205 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!DialogBoxIndirectParamA 773329B1 5 Bytes JMP 7193FEFA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!MessageBoxIndirectA 7733FAB7 5 Bytes JMP 7193FE40 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1400] USER32.dll!MessageBoxExW 7733FBB1 5 Bytes JMP 7193FDCC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!OutputDebugStringW 75AC60A7 5 Bytes JMP 28001E60 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!FindResourceExA 75AC92DD 7 Bytes JMP 28001C30 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!FindResourceA 75AC93BB 5 Bytes JMP 28001BA0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!FindResourceW 75AD33FE 5 Bytes JMP 28001A90 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!SizeofResource 75AD341C 7 Bytes JMP 28001D90 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!SetUnhandledExceptionFilter 75ADD187 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!CreateEventA 75AF7B60 5 Bytes JMP 28001850 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!LockResource 75AFD5DF 5 Bytes JMP 28001E00 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!FindResourceExW 75AFD673 7 Bytes JMP 28001B10 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] kernel32.dll!LoadResource 75AFD74B 7 Bytes JMP 28001CD0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] ADVAPI32.dll!CryptDeriveKey 75E2D229 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] ADVAPI32.dll!CryptDecrypt 75E2D359 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!SetWindowPlacement 772E74D9 5 Bytes JMP 28005860 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!TrackPopupMenuEx 772EC75F 5 Bytes JMP 280049A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!LoadImageW 772ED3C5 5 Bytes JMP 280060C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!SetWindowRgn 772EE006 7 Bytes JMP 280059A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!CreateWindowExW 772F85F0 5 Bytes JMP 28003850 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!LoadIconW 772F86D8 5 Bytes JMP 280062B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!PeekMessageW 773025BC 1 Byte [ E9 ]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!PeekMessageW + 2 773025BE 3 Bytes [ 1A, D0, B0 ]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!MessageBoxIndirectW 7730F1B3 5 Bytes JMP 28005CB0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] USER32.dll!CreateDialogParamW 7731A500 5 Bytes JMP 28005AC0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!closesocket 75F73847 5 Bytes JMP 2800A6E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!send 75F73A8A 5 Bytes JMP 2800A2C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!recv 75F74ABD 5 Bytes JMP 28009F00 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!WSASend 75F74EE9 2 Bytes JMP 2800A4A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!WSASend + 3 75F74EEC 2 Bytes [ 09, B2 ]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WS2_32.dll!WSARecv 75F772B5 5 Bytes JMP 2800A0A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] SHELL32.dll!Shell_NotifyIconW 7608310C 5 Bytes JMP 28003000 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] ole32.dll!CoRegisterClassObject 770239AC 5 Bytes JMP 28002210 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] ole32.dll!CoInitializeEx 7705885D 5 Bytes JMP 28002110 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WININET.dll!InternetCloseHandle 75C5DA79 5 Bytes JMP 28009110 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WININET.dll!HttpOpenRequestA 75C64341 5 Bytes JMP 28008DD0 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WININET.dll!InternetReadFile 75C6ABAC 5 Bytes JMP 28008F60 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1764] WININET.dll!HttpSendRequestA 75C6CD38 5 Bytes JMP 28009040 C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolIo + FFF48011 75AB1809 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTime + B 75AB181B 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTime + 11 75AB1821 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTime + 17 75AB1827 95 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTime + 77 75AB1887 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTimeAsFileTime + 8 75AB1898 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTimeAsFileTime + E 75AB189E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTimeAsFileTime + 14 75AB18A4 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetSystemTimeAsFileTime + 26 75AB18B6 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!VirtualProtect + 18 75AB18D7 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!VirtualProtect + 1C 75AB18DB 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!TerminateProcess + 9 75AB18E9 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!TerminateProcess + 22 75AB1902 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!TerminateProcess + 29 75AB1909 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!TerminateProcess + 31 75AB1911 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW + B 75AB1925 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW + 16 75AB1930 1 Byte [ 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW + 1A 75AB1934 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW + 20 75AB193A 67 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW + 64 75AB197E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA + B 75AB19C3 99 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA + 6F 75AB1A27 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA + 8C 75AB1A44 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA + 9F 75AB1A57 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA + A5 75AB1A5D 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadProcessMemory + 2D 75AB1C0F 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadProcessMemory + 3A 75AB1C1C 119 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteProcessMemory + 71 75AB1C96 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteProcessMemory + 86 75AB1CAB 81 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteProcessMemory + D8 75AB1CFD 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteProcessMemory + DE 75AB1D03 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteProcessMemory + E4 75AB1D09 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessW + 7 75AB1D2E 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessW + 27 75AB1D4E 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessW + 2C 75AB1D53 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessW + 30 75AB1D57 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessA + 7 75AB1D63 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessA + 27 75AB1D83 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessA + 2C 75AB1D88 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessA + 30 75AB1D8C 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!Sleep + 7 75AB1D98 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!Sleep + F 75AB1DA0 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!Sleep + 13 75AB1DA4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!Sleep + 26 75AB1DB7 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!Sleep + 2E 75AB1DBF 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!RegisterWaitForSingleObjectEx + C 75AB1ECF 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!RegisterWaitForSingleObjectEx + 18 75AB1EDB 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!RegisterWaitForSingleObjectEx + 21 75AB1EE4 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!RegisterWaitForSingleObjectEx + 2A 75AB1EED 3 Bytes [ 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!RegisterWaitForSingleObjectEx + 2E 75AB1EF1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!InitAtomTable + 1C 75AB1F96 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!InitAtomTable + 22 75AB1F9C 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!InitAtomTable + 35 75AB1FAF 1 Byte [ 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!InitAtomTable + 37 75AB1FB1 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!InitAtomTable + 44 75AB1FBE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetMailslotInfo + 37 75AB208E 91 Bytes [ 16, 77, 8E, 7D, 1B, 77, 0F, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetMailslotInfo + 93 75AB20EA 311 Bytes [ 1A, 77, 64, 04, 1B, 77, 59, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetThreadpoolThreadMinimum + AF 75AB2222 460 Bytes [ 1A, 77, 80, 49, 19, 77, 04, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WerRegisterFile + 1B6 75AB23EF 253 Bytes [ 77, 86, 06, 1E, 77, 79, AE, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateNamedPipeA + 69 75AB24ED 399 Bytes [ DC, 18, 77, EC, B7, 15, 77, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesW + 3A 75AB267D 425 Bytes [ 05, 1B, 77, 74, 03, 1B, 77, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesW + 1E4 75AB2827 13 Bytes [ FE, 7F, 3B, C2, 75, 5A, 89, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesW + 1F2 75AB2835 54 Bytes [ 45, F8, 50, 89, 4D, F8, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesW + 229 75AB286C 73 Bytes [ 8B, 4D, F0, 66, 89, 48, 0A, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesExW + 4 75AB28B6 21 Bytes [ F3, 90, EB, DB, 90, 90, 90, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesExW + 1B 75AB28CD 4 Bytes [ FF, 75, 08, 6A ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesExW + 20 75AB28D2 25 Bytes CALL 75AD70AB C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesExW + 3A 75AB28EC 5 Bytes [ 75, 0C, FF, 75, 08 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumResourceLanguagesExW + 40 75AB28F2 49 Bytes [ 15, BC, 14, AB, 75, 85, C0, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolTimer + C3 75AB2D79 5 Bytes [ 75, 10, FF, 75, 0C ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolTimer + C9 75AB2D7F 24 Bytes CALL 75AC917E C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolTimer + E3 75AB2D99 10 Bytes CALL 75AF888C C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolTimer + EE 75AB2DA4 18 Bytes [ FF, 75, 0C, FF, 75, 08, 68, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolTimer + 101 75AB2DB7 34 Bytes [ 3B, C3, 0F, 84, 1A, 71, 05, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!DefineDosDeviceA + 16 75AB2E8F 86 Bytes [ AB, 75, 85, C0, 0F, 8D, 34, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!DefineDosDeviceA + 6D 75AB2EE6 28 Bytes [ F6, 0F, 84, 42, 1B, 06, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!DefineDosDeviceA + 8A 75AB2F03 4 Bytes [ 84, 63, 1B, 06 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!DefineDosDeviceA + 8F 75AB2F08 42 Bytes [ FF, 75, 18, FF, 75, 14, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!DefineDosDeviceA + BA 75AB2F33 4 Bytes [ 8C, 5C, 1B, 06 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!EnumSystemLocalesW + E 75AB2F64 17 Bytes [ 90, 90, 90, 90, 90, 8B, 45, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BaseInitAppcompatCacheSupport 75AB2F76 59 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BaseInitAppcompatCacheSupport + 3C 75AB2FB2 62 Bytes [ 75, FC, 68, 68, A5, B7, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BaseInitAppcompatCacheSupport + 7B 75AB2FF1 4 Bytes [ 10, FF, 75, 0C ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BaseInitAppcompatCacheSupport + 80 75AB2FF6 2 Bytes [ 75, 08 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BaseInitAppcompatCacheSupport + 83 75AB2FF9 107 Bytes [ 15, A4, 13, AB, 75, 85, C0, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ScrollConsoleScreenBufferW + B 75AB314F 19 Bytes [ FF, 50, 8B, 85, 58, FD, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ScrollConsoleScreenBufferW + 1F 75AB3163 106 Bytes [ 8D, B5, 5C, FF, FF, FF, E9, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ScrollConsoleScreenBufferW + 8A 75AB31CE 15 Bytes [ 5D, FC, 8B, B0, 30, 02, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ScrollConsoleScreenBufferW + 9B 75AB31DF 43 Bytes CALL 75ABC559 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ScrollConsoleScreenBufferW + C8 75AB320C 8 Bytes [ FF, 8B, 45, E4, E8, 60, 56, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec + 1E 75AB32FD 9 Bytes [ 8B, 46, 2C, 03, C6, FF, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec + 29 75AB3308 2 Bytes [ 1F, 21 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec + 2D 75AB330C 4 Bytes [ 89, 45, E4, 85 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec + 32 75AB3311 20 Bytes CALL 75AB8FA6 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec + 47 75AB3326 5 Bytes [ 00, 00, 8B, 45, E4 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetComputerNameExA + B 75AB33B7 62 Bytes [ 89, 7D, FC, 8B, B3, 30, 02, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetComputerNameExA + 4A 75AB33F6 22 Bytes CALL 75AB3427 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetComputerNameExA + 61 75AB340D 12 Bytes [ 00, 00, 00, CC, FF, FF, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetComputerNameExA + 6F 75AB341B 35 Bytes [ FF, 00, 00, 00, 00, 29, 24, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetComputerNameExA + 93 75AB343F 11 Bytes [ 01, 00, 00, FF, 75, 08, 50, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!QueryInformationJobObject + 17 75AB3695 13 Bytes JMP 75B10619 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!QueryInformationJobObject + 25 75AB36A3 23 Bytes [ 85, B0, F5, FF, FF, 50, 8D, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!QueryInformationJobObject + 3D 75AB36BB 46 Bytes [ FF, 50, 8D, 85, 60, F5, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!QueryInformationJobObject + 6C 75AB36EA 20 Bytes JMP 75AB37FF C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!QueryInformationJobObject + 81 75AB36FF 16 Bytes [ 00, A1, AC, A4, B7, 75, 33, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!OpenFile + 23 75AB380F 65 Bytes CALL 75AF5EBC C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!OpenFile + 65 75AB3851 17 Bytes [ 89, 85, E0, FE, FF, FF, 3B, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!OpenFile + 77 75AB3863 15 Bytes [ 00, 00, 8B, 85, D8, FE, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!OpenFile + 88 75AB3874 9 Bytes [ 85, D8, FE, FF, FF, FF, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!OpenFile + 92 75AB387E 4 Bytes [ B5, B0, FE, FF ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetVolumeInformationA + C 75AB3DA2 195 Bytes [ 00, 00, 8B, 40, 30, 6A, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetVolumeInformationA + D0 75AB3E66 46 Bytes [ 8B, C6, 5E, C9, C2, 04, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetVolumeInformationA + FF 75AB3E95 2 Bytes [ 74, 39 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetVolumeInformationA + 102 75AB3E98 44 Bytes [ 75, 10, 8D, 45, F8, 50, E8, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNumberOfConsoleInputEvents + 19 75AB3EC5 21 Bytes [ C7, 5F, 5E, C9, C2, 0C, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNumberOfConsoleInputEvents + 2F 75AB3EDB 28 Bytes [ 55, 8B, EC, 51, 51, FF, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNumberOfConsoleInputEvents + 4C 75AB3EF8 47 Bytes [ 75, 08, FF, 15, A0, 10, AB, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNumberOfConsoleInputEvents + 7C 75AB3F28 7 Bytes [ 85, C0, 0F, 85, 69, 16, 04 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNumberOfConsoleInputEvents + 84 75AB3F30 17 Bytes [ 85, DB, 0F, 85, CB, 5C, 05, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWork + 27 75AB40A2 13 Bytes [ 72, 00, 69, 00, 76, 00, 65, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWork + 35 75AB40B0 5 Bytes [ 45, 00, 4D, 00, 50 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWork + 3B 75AB40B6 5 Bytes [ 00, 00, B8, 80, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWork + 41 75AB40BC 9 Bytes JMP 75AB9760 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWork + 4B 75AB40C6 74 Bytes JMP 75AB9760 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteFileEx + 39 75AB4112 74 Bytes JMP 75ABF001 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteFileEx + 84 75AB415D 31 Bytes [ 00, 00, 5D, C2, 14, 00, 90, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteFileEx + A4 75AB417D 65 Bytes [ 8B, 40, 30, 8B, 40, 10, 8B, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteFileEx + E6 75AB41BF 7 Bytes [ 89, 75, 84, 8B, 45, 18, 8B ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WriteFileEx + EE 75AB41C7 141 Bytes [ 89, 45, 8C, 8B, 45, 14, 89, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateDirectoryA + C 75AB42AD 58 Bytes [ EB, DF, C7, 45, 20, 02, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateDirectoryA + 47 75AB42E8 22 Bytes [ 00, 00, 53, 8B, 5D, 0C, 56, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateDirectoryA + 5E 75AB42FF 95 Bytes [ 0C, 6A, 44, 8D, 45, 80, 56, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadFileScatter + E 75AB435F 53 Bytes CALL 85F778EF
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadFileScatter + 44 75AB4395 75 Bytes [ 45, 0C, 50, 8D, 45, F8, 50, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadFileScatter + 90 75AB43E1 6 Bytes [ 00, 0F, 84, CC, 5F, 05 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!ReadFileScatter + 97 75AB43E8 116 Bytes [ 85, C0, 0F, 84, 3E, 5F, 05, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNLSVersion + 6E 75AB445D 6 Bytes [ 40, 00, 00, E9, 9A, 02 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNLSVersion + 75 75AB4464 4 Bytes [ 00, C7, 45, B4 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNLSVersion + 7A 75AB4469 6 Bytes [ 01, 00, 00, E9, 8E, 02 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNLSVersion + 81 75AB4470 107 Bytes [ 00, C7, 45, B4, 80, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetNLSVersion + ED 75AB44DC 19 Bytes [ 83, 3E, 03, 0F, 84, 98, 6E, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BindIoCompletionCallback + 23 75AB4518 44 Bytes JMP 75ABA6DB C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BindIoCompletionCallback + 50 75AB4545 32 Bytes [ 8D, 85, 4C, FF, FF, FF, 50, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BindIoCompletionCallback + 71 75AB4566 7 Bytes [ 00, 57, 8D, 85, 24, FF, FF ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BindIoCompletionCallback + 79 75AB456E 73 Bytes [ 50, FF, 15, 48, 10, AB, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!BindIoCompletionCallback + C3 75AB45B8 20 Bytes [ B5, 2C, FF, FF, FF, FF, B5, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetThreadAffinityMask + 3F 75AB468D 61 Bytes [ 7D, 14, 0F, 84, 0F, 11, 06, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetThreadAffinityMask + 7D 75AB46CB 12 Bytes [ 3B, F0, 75, 40, 8B, 45, B4, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotW + A 75AB46D8 23 Bytes [ FF, 48, 74, 1C, 48, 0F, 84, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotW + 22 75AB46F0 17 Bytes [ FF, 48, 0F, 84, C5, 10, 06, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotW + 34 75AB4702 21 Bytes [ 90, 50, FF, 75, 10, E8, FB, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotW + 4A 75AB4718 7 Bytes [ F7, 85, B8, FD, FF, FF, 00 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotW + 52 75AB4720 1 Byte [ 20 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotA + B 75AB47C1 16 Bytes [ FF, 15, B8, 14, AB, 75, 5D, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateMailslotA + 1C 75AB47D2 152 Bytes CALL 75AF919D C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetMailslotInfo + 63 75AB486B 60 Bytes [ 2C, FF, FF, FF, C7, 85, 40, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerA + 2 75AB48A8 16 Bytes CALL 75ABBF9B C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerA + 13 75AB48B9 11 Bytes [ 3B, C6, 75, 30, C7, 85, 4C, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerA + 21 75AB48C7 10 Bytes [ 8D, 85, 3C, FF, FF, FF, 50, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerExA + 2 75AB48D2 31 Bytes [ B5, 48, FF, FF, FF, E8, 9D, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerExA + 22 75AB48F2 11 Bytes [ 40, 0F, 84, A6, FC, FF, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerExA + 2E 75AB48FE 46 Bytes [ FF, 0F, 85, 9A, FC, FF, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerExA + 5D 75AB492D 20 Bytes [ 58, FF, FF, FF, 01, 00, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateWaitableTimerExA + 72 75AB4942 3 Bytes [ 00, 00, 8B ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CancelIo + 4 75AB4AE8 3 Bytes [ F8, 6A, 01 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CancelIo + 9 75AB4AED 1 Byte [ F4 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CancelIo + B 75AB4AEF 27 Bytes [ 8D, 45, EC, 50, FF, 15, 90, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CancelIo + 27 75AB4B0B 210 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CancelIo + FA 75AB4BDE 11 Bytes [ 46, 00, 4F, 00, 00, 00, 50, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetClientTimeZoneInformation + 20 75AB4D69 21 Bytes JMP 75AB6B27 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetClientTimeZoneInformation + 36 75AB4D7F 111 Bytes [ 8B, 40, 08, 89, 46, 08, C7, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetClientTimeZoneInformation + A6 75AB4DEF 5 Bytes [ 75, FC, 3B, CE, 0F ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetClientTimeZoneInformation + AC 75AB4DF5 95 Bytes [ 7D, B2, 04, 00, 39, 75, 20, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!SetClientTimeZoneInformation + 10C 75AB4E55 42 Bytes [ 00, 00, 00, B4, FF, FF, FF, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindVolumeClose + 22 75AB4F84 35 Bytes [ 59, 39, 4E, 04, 75, 35, 85, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindNextVolumeW + 10 75AB4FA8 1 Byte [ 4E ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindNextVolumeW + 12 75AB4FAA 80 Bytes [ 8B, 09, 89, 48, 0C, 89, 4D, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindNextVolumeW + 63 75AB4FFB 32 Bytes [ 00, BA, 00, 00, 00, 40, E9, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindNextVolumeW + 84 75AB501C 26 Bytes [ 8D, 45, FC, 50, FF, 15, 60, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindNextVolumeW + 9F 75AB5037 82 Bytes [ 15, 34, 11, AB, 75, 53, FF, ... ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindFirstVolumeW + B 75AB5247 6 Bytes [ FF, 8B, D1, 81, E2, E0 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindFirstVolumeW + 12 75AB524E 164 Bytes [ 00, 00, 0F, 84, 68, 19, 00, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindFirstVolumeW + B7 75AB52F3 100 Bytes JMP 4025FF90
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!FindFirstVolumeW + 11C 75AB5358 56 Bytes CALL 75AF8830 C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWait + 4 75AB5391 7 Bytes [ 48, 10, 57, 8D, 55, E0, 52 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWait + D 75AB539A 1 Byte [ 10 ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWait + 10 75AB539D 1 Byte [ 0C ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWait + 12 75AB539F 54 Bytes [ 8B, D1, 80, E2, 01, F6, DA, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateThreadpoolWait + 49 75AB53D6 6 Bytes [ 00, 33, C0, E8, 97, 34 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!PrivCopyFileExW + 26 75AB54B6 12 Bytes [ 48, 04, 8B, 0D, F4, 9B, AD, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!PrivCopyFileExW + 33 75AB54C3 24 Bytes [ 00, 33, F6, 46, 3B, D6, 89, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!PrivCopyFileExW + 4C 75AB54DC 30 Bytes [ 33, C0, 5F, 40, 5E, 5B, 8B, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!PrivCopyFileExW + 6B 75AB54FB 28 Bytes [ 75, 10, FF, 75, 0C, FF, 75, ... ]
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!PrivCopyFileExW + 88 75AB5518 5 Bytes [ 66, C7, 45, D8, 06 ]
.text ...
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WerpNotifyUseStringResource + 20