GMER Teil1 Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-18 13:38:30
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 Samsung_SSD_840_EVO_250GB rev.EXT0BB6Q 232,89GB
Running: Gmer-19357(1).exe; Driver: C:\Users\Alex\AppData\Local\Temp\kxldrpog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, F0, 12, 80, 01]
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[988] C:\Windows\system32\kernel32.dll!UnhandledExceptionFilter + 1 0000000076d5b7e1 11 bytes [B8, F0, 12, 74, 01, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000076f31780 6 bytes [48, B8, 39, 2A, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000076f31788 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076f31790 6 bytes [48, B8, B9, 26, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000076f31798 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000076f31cd0 6 bytes [48, B8, 79, 28, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000076f31cd8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076f31d30 6 bytes [48, B8, F9, 24, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000076f31d38 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076f320a0 6 bytes [48, B8, 79, D7, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 0000000076f320a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError 0000000076f325e0 6 bytes [48, B8, 79, 83, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 0000000076f325e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076f327e0 6 bytes [48, B8, 39, 31, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 0000000076f327e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076f329a0 6 bytes [48, B8, 39, D9, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 0000000076f329a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076f32a80 6 bytes [48, B8, 79, 3D, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000076f32a88 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076f32a90 6 bytes [48, B8, B9, 3B, 77, 75]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000076f32a98 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000076fa3201 11 bytes [B8, 39, 85, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!Process32NextW + 1 0000000076cc1b21 11 bytes [B8, F9, D3, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000076cc1c10 12 bytes [48, B8, F9, 39, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076cddb80 12 bytes [48, B8, B9, 2D, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000076ce0931 11 bytes [B8, 79, E5, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!ReadConsoleInputW + 1 0000000076d152f1 11 bytes [B8, B9, 7A, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000076d15311 11 bytes [B8, 39, 77, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!ReadConsoleW 0000000076d2a5e0 12 bytes [48, B8, B9, 81, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!ReadConsoleA 0000000076d2a6f0 12 bytes [48, B8, 39, 7E, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefcd81861 11 bytes [B8, 79, 52, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefcd82db1 11 bytes [B8, B9, C7, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefcd83461 11 bytes [B8, 79, C9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcd88ef0 12 bytes [48, B8, F9, C5, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fefcd894c0 12 bytes [48, B8, B9, 50, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefcd8bfd1 11 bytes [B8, 39, C4, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefcd92af1 11 bytes [B8, F9, 4E, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefcdb4350 12 bytes [48, B8, B9, 42, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefcdc2871 8 bytes [B8, 39, 23, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefcdc287a 2 bytes [50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefcdc28b1 11 bytes [B8, F9, 40, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefd4f642d 11 bytes [B8, 39, 5B, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefd4f6484 12 bytes [48, B8, F9, 55, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefd4f6519 11 bytes [B8, 39, 62, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefd4f6c34 12 bytes [48, B8, 39, 54, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefd4f7ab5 11 bytes [B8, F9, 5C, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefd4f8b01 11 bytes [B8, B9, 57, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefd4f8c39 11 bytes [B8, 79, 59, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\ADVAPI32.dll!IsTextUnicode + 49 000007feff094ea1 11 bytes [B8, 39, E7, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 000007feff0955c8 12 bytes [48, B8, B9, 6C, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 000007feff0ab85c 12 bytes [48, B8, F9, 6A, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigW 000007feff0ab9d0 12 bytes [48, B8, 79, 60, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigA 000007feff0aba3c 12 bytes [48, B8, B9, 5E, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!WSASend + 1 000007fefee513b1 11 bytes [B8, F9, BE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!closesocket 000007fefee518e0 12 bytes [48, B8, 39, BD, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!WSASocketW + 1 000007fefee51bd1 11 bytes [B8, 79, BB, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!WSARecv + 1 000007fefee52201 11 bytes [B8, F9, E1, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 000007fefee523c0 12 bytes [48, B8, 79, A6, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!connect 000007fefee545c0 12 bytes [48, B8, 79, 67, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!send + 1 000007fefee58001 11 bytes [B8, B9, B9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefee58df0 7 bytes [48, B8, 39, A8, 77, 75, 00]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!gethostbyname + 9 000007fefee58df9 3 bytes [00, 50, C3]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!socket + 1 000007fefee5de91 11 bytes [B8, F9, DA, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!recv + 1 000007fefee5df41 11 bytes [B8, 39, E0, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 000007fefee7e0f1 11 bytes [B8, 79, DE, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000076f31780 6 bytes [48, B8, 39, 2A, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000076f31788 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076f31790 6 bytes [48, B8, B9, 26, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000076f31798 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000076f31cd0 6 bytes [48, B8, 79, 28, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000076f31cd8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076f31d30 6 bytes [48, B8, F9, 24, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000076f31d38 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076f320a0 6 bytes [48, B8, 79, D7, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 0000000076f320a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError 0000000076f325e0 6 bytes [48, B8, 79, 83, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 0000000076f325e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076f327e0 6 bytes [48, B8, 39, 31, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 0000000076f327e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076f329a0 6 bytes [48, B8, 39, D9, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 0000000076f329a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076f32a80 6 bytes [48, B8, 79, 3D, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000076f32a88 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076f32a90 6 bytes [48, B8, B9, 3B, 77, 75]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000076f32a98 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000076fa3201 11 bytes [B8, 39, 85, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!Process32NextW + 1 0000000076cc1b21 11 bytes [B8, F9, D3, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000076cc1c10 12 bytes [48, B8, F9, 39, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076cddb80 12 bytes [48, B8, B9, 2D, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000076ce0931 11 bytes [B8, 79, E5, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!ReadConsoleInputW + 1 0000000076d152f1 11 bytes [B8, B9, 7A, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000076d15311 11 bytes [B8, 39, 77, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!ReadConsoleW 0000000076d2a5e0 12 bytes [48, B8, B9, 81, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\kernel32.dll!ReadConsoleA 0000000076d2a6f0 12 bytes [48, B8, 39, 7E, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefcd81861 11 bytes [B8, 79, 52, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefcd82db1 11 bytes [B8, B9, C7, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefcd83461 11 bytes [B8, 79, C9, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcd88ef0 12 bytes [48, B8, F9, C5, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fefcd894c0 12 bytes [48, B8, B9, 50, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefcd8bfd1 11 bytes [B8, 39, C4, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefcd92af1 11 bytes [B8, F9, 4E, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefcdb4350 12 bytes [48, B8, B9, 42, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefcdc2871 8 bytes [B8, 39, 23, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefcdc287a 2 bytes [50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefcdc28b1 11 bytes [B8, F9, 40, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefd4f642d 11 bytes [B8, 39, 5B, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefd4f6484 12 bytes [48, B8, F9, 55, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefd4f6519 11 bytes [B8, 39, 62, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefd4f6c34 12 bytes [48, B8, 39, 54, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefd4f7ab5 11 bytes [B8, F9, 5C, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefd4f8b01 11 bytes [B8, B9, 57, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefd4f8c39 11 bytes [B8, 79, 59, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\ADVAPI32.dll!IsTextUnicode + 49 000007feff094ea1 11 bytes [B8, F9, E8, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 000007feff0955c8 12 bytes [48, B8, B9, 6C, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 000007feff0ab85c 12 bytes [48, B8, F9, 6A, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigW 000007feff0ab9d0 12 bytes [48, B8, 79, 60, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigA 000007feff0aba3c 12 bytes [48, B8, B9, 5E, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!WSASend + 1 000007fefee513b1 11 bytes [B8, F9, BE, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!closesocket 000007fefee518e0 12 bytes [48, B8, 39, BD, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!WSASocketW + 1 000007fefee51bd1 11 bytes [B8, 79, BB, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!WSARecv + 1 000007fefee52201 11 bytes [B8, F9, E1, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 000007fefee523c0 12 bytes [48, B8, 79, A6, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!connect 000007fefee545c0 12 bytes [48, B8, 79, 67, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!send + 1 000007fefee58001 11 bytes [B8, B9, B9, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefee58df0 7 bytes [48, B8, 39, A8, 77, 75, 00]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!gethostbyname + 9 000007fefee58df9 3 bytes [00, 50, C3]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!socket + 1 000007fefee5de91 11 bytes [B8, F9, DA, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!recv + 1 000007fefee5df41 11 bytes [B8, 39, E0, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1336] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 000007fefee7e0f1 11 bytes [B8, 79, DE, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000076f31780 6 bytes [48, B8, 39, 2A, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000076f31788 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076f31790 6 bytes [48, B8, B9, 26, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000076f31798 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000076f31cd0 6 bytes [48, B8, 79, 28, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000076f31cd8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076f31d30 6 bytes [48, B8, F9, 24, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000076f31d38 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076f320a0 6 bytes [48, B8, 79, D7, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 0000000076f320a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError 0000000076f325e0 6 bytes [48, B8, 79, 83, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 0000000076f325e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076f327e0 6 bytes [48, B8, 39, 31, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 0000000076f327e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076f329a0 6 bytes [48, B8, 39, D9, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 0000000076f329a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076f32a80 6 bytes [48, B8, 79, 3D, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000076f32a88 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076f32a90 6 bytes [48, B8, B9, 3B, 77, 75]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000076f32a98 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000076fa3201 11 bytes [B8, 39, 85, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!Process32NextW + 1 0000000076cc1b21 11 bytes [B8, F9, D3, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000076cc1c10 12 bytes [48, B8, F9, 39, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076cddb80 12 bytes [48, B8, B9, 2D, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000076ce0931 11 bytes [B8, 79, E5, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!ReadConsoleInputW + 1 0000000076d152f1 11 bytes [B8, B9, 7A, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000076d15311 11 bytes [B8, 39, 77, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!ReadConsoleW 0000000076d2a5e0 12 bytes [48, B8, B9, 81, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\kernel32.dll!ReadConsoleA 0000000076d2a6f0 12 bytes [48, B8, 39, 7E, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefcd81861 11 bytes [B8, 79, 52, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefcd82db1 11 bytes [B8, B9, C7, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefcd83461 11 bytes [B8, 79, C9, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcd88ef0 12 bytes [48, B8, F9, C5, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fefcd894c0 12 bytes [48, B8, B9, 50, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefcd8bfd1 11 bytes [B8, 39, C4, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefcd92af1 11 bytes [B8, F9, 4E, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefcdb4350 12 bytes [48, B8, B9, 42, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefcdc2871 8 bytes [B8, 39, 23, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefcdc287a 2 bytes [50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefcdc28b1 11 bytes [B8, F9, 40, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefd4f642d 11 bytes [B8, 39, 5B, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefd4f6484 12 bytes [48, B8, F9, 55, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefd4f6519 11 bytes [B8, 39, 62, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefd4f6c34 12 bytes [48, B8, 39, 54, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefd4f7ab5 11 bytes [B8, F9, 5C, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefd4f8b01 11 bytes [B8, B9, 57, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefd4f8c39 11 bytes [B8, 79, 59, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!WSASend + 1 000007fefee513b1 11 bytes [B8, F9, BE, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!closesocket 000007fefee518e0 12 bytes [48, B8, 39, BD, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!WSASocketW + 1 000007fefee51bd1 11 bytes [B8, 79, BB, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!WSARecv + 1 000007fefee52201 11 bytes [B8, F9, E1, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 000007fefee523c0 12 bytes [48, B8, 79, A6, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!connect 000007fefee545c0 12 bytes [48, B8, 79, 67, 77, 75, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!send + 1 000007fefee58001 11 bytes [B8, B9, B9, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefee58df0 7 bytes [48, B8, 39, A8, 77, 75, 00]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!gethostbyname + 9 000007fefee58df9 3 bytes [00, 50, C3]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!socket + 1 000007fefee5de91 11 bytes [B8, F9, DA, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!recv + 1 000007fefee5df41 11 bytes [B8, 39, E0, 77, 75, 00, 00, ...]
.text C:\Windows\System32\svchost.exe[1384] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 000007fefee7e0f1 11 bytes [B8, 79, DE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000076f31780 6 bytes [48, B8, 39, 2A, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000076f31788 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076f31790 6 bytes [48, B8, B9, 26, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000076f31798 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000076f31cd0 6 bytes [48, B8, 79, 28, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000076f31cd8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076f31d30 6 bytes [48, B8, F9, 24, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000076f31d38 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076f320a0 6 bytes [48, B8, 79, D7, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 0000000076f320a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError 0000000076f325e0 6 bytes [48, B8, 79, 83, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 0000000076f325e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076f327e0 6 bytes [48, B8, 39, 31, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 0000000076f327e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076f329a0 6 bytes [48, B8, 39, D9, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 0000000076f329a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076f32a80 6 bytes [48, B8, 79, 3D, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000076f32a88 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076f32a90 6 bytes [48, B8, B9, 3B, 77, 75]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000076f32a98 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000076fa3201 11 bytes [B8, 39, 85, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!Process32NextW + 1 0000000076cc1b21 11 bytes [B8, F9, D3, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000076cc1c10 12 bytes [48, B8, F9, 39, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076cddb80 12 bytes [48, B8, B9, 2D, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000076ce0931 11 bytes [B8, 79, E5, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!ReadConsoleInputW + 1 0000000076d152f1 11 bytes [B8, B9, 7A, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000076d15311 11 bytes [B8, 39, 77, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!ReadConsoleW 0000000076d2a5e0 12 bytes [48, B8, B9, 81, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\kernel32.dll!ReadConsoleA 0000000076d2a6f0 12 bytes [48, B8, 39, 7E, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefcd81861 11 bytes [B8, 79, 52, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefcd82db1 11 bytes [B8, B9, C7, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefcd83461 11 bytes [B8, 79, C9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcd88ef0 12 bytes [48, B8, F9, C5, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fefcd894c0 12 bytes [48, B8, B9, 50, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefcd8bfd1 11 bytes [B8, 39, C4, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefcd92af1 11 bytes [B8, F9, 4E, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefcdb4350 12 bytes [48, B8, B9, 42, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefcdc2871 8 bytes [B8, 39, 23, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefcdc287a 2 bytes [50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefcdc28b1 11 bytes [B8, F9, 40, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefd4f642d 11 bytes [B8, 39, 5B, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefd4f6484 12 bytes [48, B8, F9, 55, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefd4f6519 11 bytes [B8, 39, 62, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefd4f6c34 12 bytes [48, B8, 39, 54, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefd4f7ab5 11 bytes [B8, F9, 5C, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefd4f8b01 11 bytes [B8, B9, 57, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefd4f8c39 11 bytes [B8, 79, 59, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!WSASend + 1 000007fefee513b1 11 bytes [B8, F9, BE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!closesocket 000007fefee518e0 12 bytes [48, B8, 39, BD, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!WSASocketW + 1 000007fefee51bd1 11 bytes [B8, 79, BB, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!WSARecv + 1 000007fefee52201 11 bytes [B8, F9, E1, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 000007fefee523c0 12 bytes [48, B8, 79, A6, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!connect 000007fefee545c0 12 bytes [48, B8, 79, 67, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!send + 1 000007fefee58001 11 bytes [B8, B9, B9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefee58df0 7 bytes [48, B8, 39, A8, 77, 75, 00]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!gethostbyname + 9 000007fefee58df9 3 bytes [00, 50, C3]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!socket + 1 000007fefee5de91 11 bytes [B8, F9, DA, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!recv + 1 000007fefee5df41 11 bytes [B8, 39, E0, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1408] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 000007fefee7e0f1 11 bytes [B8, 79, DE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000076f31780 6 bytes [48, B8, 39, 2A, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000076f31788 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076f31790 6 bytes [48, B8, B9, 26, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000076f31798 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000076f31cd0 6 bytes [48, B8, 79, 28, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000076f31cd8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076f31d30 6 bytes [48, B8, F9, 24, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000076f31d38 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076f320a0 6 bytes [48, B8, 79, D7, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 0000000076f320a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError 0000000076f325e0 6 bytes [48, B8, 79, 83, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 0000000076f325e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076f327e0 6 bytes [48, B8, 39, 31, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 0000000076f327e8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076f329a0 6 bytes [48, B8, 39, D9, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 0000000076f329a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076f32a80 6 bytes [48, B8, 79, 3D, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000076f32a88 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076f32a90 6 bytes [48, B8, B9, 3B, 77, 75]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000076f32a98 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000076fa3201 11 bytes [B8, 39, 85, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!Process32NextW + 1 0000000076cc1b21 11 bytes [B8, F9, D3, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000076cc1c10 12 bytes [48, B8, F9, 39, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076cddb80 12 bytes [48, B8, B9, 2D, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000076ce0931 11 bytes [B8, 79, E5, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!ReadConsoleInputW + 1 0000000076d152f1 11 bytes [B8, B9, 7A, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000076d15311 11 bytes [B8, 39, 77, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!ReadConsoleW 0000000076d2a5e0 12 bytes [48, B8, B9, 81, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\kernel32.dll!ReadConsoleA 0000000076d2a6f0 12 bytes [48, B8, 39, 7E, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefcd81861 11 bytes [B8, 79, 52, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefcd82db1 11 bytes [B8, B9, C7, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefcd83461 11 bytes [B8, 79, C9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcd88ef0 12 bytes [48, B8, F9, C5, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fefcd894c0 12 bytes [48, B8, B9, 50, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefcd8bfd1 11 bytes [B8, 39, C4, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefcd92af1 11 bytes [B8, F9, 4E, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefcdb4350 12 bytes [48, B8, B9, 42, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefcdc2871 8 bytes [B8, 39, 23, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefcdc287a 2 bytes [50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefcdc28b1 11 bytes [B8, F9, 40, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefd4f642d 11 bytes [B8, 39, 5B, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefd4f6484 12 bytes [48, B8, F9, 55, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefd4f6519 11 bytes [B8, 39, 62, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefd4f6c34 12 bytes [48, B8, 39, 54, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefd4f7ab5 11 bytes [B8, F9, 5C, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefd4f8b01 11 bytes [B8, B9, 57, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefd4f8c39 11 bytes [B8, 79, 59, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\ADVAPI32.dll!IsTextUnicode + 49 000007feff094ea1 11 bytes [B8, F9, E8, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 000007feff0955c8 12 bytes [48, B8, B9, 6C, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 000007feff0ab85c 12 bytes [48, B8, F9, 6A, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigW 000007feff0ab9d0 12 bytes [48, B8, 79, 60, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\ADVAPI32.dll!ChangeServiceConfigA 000007feff0aba3c 12 bytes [48, B8, B9, 5E, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!WSASend + 1 000007fefee513b1 11 bytes [B8, F9, BE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!closesocket 000007fefee518e0 12 bytes [48, B8, 39, BD, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!WSASocketW + 1 000007fefee51bd1 11 bytes [B8, 79, BB, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!WSARecv + 1 000007fefee52201 11 bytes [B8, F9, E1, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 000007fefee523c0 12 bytes [48, B8, 79, A6, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!connect 000007fefee545c0 12 bytes [48, B8, 79, 67, 77, 75, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!send + 1 000007fefee58001 11 bytes [B8, B9, B9, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefee58df0 7 bytes [48, B8, 39, A8, 77, 75, 00]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!gethostbyname + 9 000007fefee58df9 3 bytes [00, 50, C3]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!socket + 1 000007fefee5de91 11 bytes [B8, F9, DA, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!recv + 1 000007fefee5df41 11 bytes [B8, 39, E0, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 000007fefee7e0f1 11 bytes [B8, 79, DE, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1440] C:\Windows\system32\SHELL32.dll!Shell_NotifyIconW + 1 000007fefe0ddc81 11 bytes [B8, 79, 8A, 77, 75, 00, 00, ...]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 0000000076f192d1 5 bytes [B8, 39, 69, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 0000000076f192d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000076f313a0 6 bytes [48, B8, B9, D5, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 8 0000000076f313a8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000076f31470 6 bytes [48, B8, 79, C2, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000076f31478 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076f31510 6 bytes [48, B8, F9, 32, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000076f31518 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076f31530 6 bytes [48, B8, 39, 1C, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000076f31538 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000076f31550 6 bytes [48, B8, F9, 1D, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000076f31558 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076f31570 6 bytes [48, B8, B9, C0, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000076f31578 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076f31650 6 bytes [48, B8, 79, 2F, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000076f31658 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076f31670 6 bytes [48, B8, 79, 36, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000076f31678 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076f31700 6 bytes [48, B8, B9, 34, 77, 75]
.text C:\Windows\system32\svchost.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000076f31708 4 bytes [00, 00, 50, C3] |