Gmer.txt (5/6) Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-27 00:31:48
Page 5/6
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ffac721db10 12 bytes [48, B8, 89, 36, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!Process32NextW 00007ffac721e1f0 12 bytes [48, B8, 89, B4, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ffac72b34b1 11 bytes [B8, 89, F3, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 1 00007ffac72daba1 8 bytes [B8, 09, C6, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 10 00007ffac72dabaa 2 bytes [50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ffac72daca1 11 bytes [B8, 49, CB, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CloseHandle 00007ffac48614c0 12 bytes [48, B8, 09, 4F, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary + 1 00007ffac48621d1 11 bytes [B8, 49, A8, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!GetProcAddress 00007ffac48642a0 12 bytes [48, B8, 09, AA, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!DeviceIoControl + 1 00007ffac4865f71 11 bytes [B8, 49, D2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateMutexW 00007ffac4866ed0 12 bytes [48, B8, 49, 4D, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!OpenMutexW + 1 00007ffac4868a71 11 bytes [B8, 89, 4B, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ffac4868d81 11 bytes [B8, 49, 1C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ffac48697b1 11 bytes [B8, 89, A6, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!FindFirstFileExW 00007ffac486c050 12 bytes [48, B8, 09, D4, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!FindNextFileW + 1 00007ffac486d781 11 bytes [B8, C9, D5, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ffac4872511 11 bytes [B8, 09, CD, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ffac487ef70 12 bytes [48, B8, 49, 2A, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ffac4896b21 11 bytes [B8, 49, 3F, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 1 00007ffac48b93c1 8 bytes [B8, C9, C7, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 10 00007ffac48b93ca 2 bytes [50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ffac48da841 11 bytes [B8, 89, C2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread 00007ffac48dac50 4 bytes [48, B8, 89, 3D]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread + 5 00007ffac48dac55 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ffac492f811 11 bytes [B8, 09, 72, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ffac492f891 11 bytes [B8, C9, 73, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleA 00007ffac4930340 12 bytes [48, B8, 89, 75, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleW 00007ffac4930570 12 bytes [48, B8, 49, 77, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread 00007ffac4940c80 4 bytes [48, B8, 89, 21]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread + 5 00007ffac4940c85 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!ShowWindow 00007ffac52611b0 6 bytes [48, B8, 89, 8A, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!ShowWindow + 8 00007ffac52611b8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx 00007ffac5261210 6 bytes [48, B8, 49, 7E, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ffac5261218 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!GetMessageW 00007ffac5262670 12 bytes [48, B8, C9, 6C, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!PeekMessageW + 1 00007ffac5262991 11 bytes [B8, 49, 70, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CallNextHookEx 00007ffac5262ef0 12 bytes [48, B8, 89, 7C, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!PostMessageW + 1 00007ffac52633f1 11 bytes [B8, C9, F8, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!GetMessageA + 1 00007ffac5266191 11 bytes [B8, 09, 6B, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 1 00007ffac5266391 3 bytes [B8, C9, 1F]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 5 00007ffac5266395 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffac5266d90 7 bytes [48, B8, 09, 87, 83, 6A, 00]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CreateWindowExW + 10 00007ffac5266d9a 2 bytes [50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CreateWindowExA 00007ffac526ab30 7 bytes [48, B8, C9, 88, 83, 6A, 00]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CreateWindowExA + 10 00007ffac526ab3a 2 bytes [50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowTextW + 1 00007ffac526ce31 11 bytes [B8, 09, 95, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!PeekMessageA + 1 00007ffac526db41 11 bytes [B8, 89, 6E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!UserClientDllInitialize + 1 00007ffac526dec1 11 bytes [B8, 09, 05, 84, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowW + 1 00007ffac5270e61 3 bytes [B8, 49, AF]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowW + 5 00007ffac5270e65 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWinEventHook 00007ffac5277100 12 bytes [48, B8, C9, 3B, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ffac5283ab1 11 bytes [B8, 49, 8C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!PostMessageA + 1 00007ffac5285921 11 bytes [B8, 09, F7, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowExW + 1 00007ffac5287161 11 bytes [B8, 09, B1, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 1 00007ffac5287691 5 bytes [B8, 89, AD, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 9 00007ffac5287699 3 bytes [00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ffac52977a1 11 bytes [B8, 09, 8E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 1 00007ffac52c0f61 8 bytes [B8, 09, 1E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 10 00007ffac52c0f6a 2 bytes [50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!MessageBoxExA + 1 00007ffac52e7d01 11 bytes [B8, C9, 8F, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!MessageBoxExW + 1 00007ffac52e7d31 11 bytes [B8, 89, 91, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!SetWindowTextA + 1 00007ffac52f1021 11 bytes [B8, 49, 93, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\USER32.dll!FindWindowA + 1 00007ffac52f1471 11 bytes [B8, C9, AB, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!closesocket 00007ffac4f11be0 12 bytes [48, B8, 89, 9F, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!recv + 1 00007ffac4f12571 11 bytes [B8, C9, E3, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!WSASend + 1 00007ffac4f12d61 11 bytes [B8, 49, A1, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!WSARecv + 1 00007ffac4f12ff1 11 bytes [B8, 89, E5, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!WSASocketW 00007ffac4f13880 12 bytes [48, B8, C9, 9D, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!socket + 1 00007ffac4f13bd1 11 bytes [B8, 89, DE, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoW 00007ffac4f14230 12 bytes [48, B8, C9, 81, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!connect 00007ffac4f15730 12 bytes [48, B8, 09, 64, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoExW 00007ffac4f187e0 12 bytes [48, B8, 89, 83, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!send + 1 00007ffac4f242d1 11 bytes [B8, 09, 9C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!WSAConnect + 1 00007ffac4f26fe1 11 bytes [B8, 09, E2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\WS2_32.dll!gethostbyname + 1 00007ffac4f354b1 11 bytes [B8, 49, 85, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 1 00007ffac71514a1 5 bytes [B8, 49, D9, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 7 00007ffac71514a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 1 00007ffac7152041 5 bytes [B8, 09, E9, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 7 00007ffac7152047 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 1 00007ffac7152061 5 bytes [B8, 49, EE, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 7 00007ffac7152067 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 1 00007ffac7152071 5 bytes [B8, 89, EC, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 7 00007ffac7152077 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 1 00007ffac7152091 5 bytes [B8, 09, F0, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 7 00007ffac7152097 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 1 00007ffac71520a1 5 bytes [B8, C9, EA, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 7 00007ffac71520a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 1 00007ffac7152201 5 bytes [B8, 89, D7, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 7 00007ffac7152207 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 1 00007ffac7180fa1 5 bytes [B8, 09, DB, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 7 00007ffac7180fa7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 1 00007ffac7180fb1 5 bytes [B8, C9, DC, 83, 6A]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 7 00007ffac7180fb7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA 00007ffac71add10 4 bytes [48, B8, 89, 67]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA + 5 00007ffac71add15 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW 00007ffac71adda0 4 bytes [48, B8, 49, 69]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW + 5 00007ffac71adda5 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ffac570bb11 11 bytes [B8, 09, 80, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ffac4df47a1 11 bytes [B8, C9, 5E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceW 00007ffac4df4d10 12 bytes [48, B8, 89, 52, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceA 00007ffac4dfa830 12 bytes [48, B8, C9, 50, 83, 6A, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!ControlService + 1 00007ffac4dfae11 11 bytes [B8, C9, 57, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ffac4dfed61 11 bytes [B8, 09, 56, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ffac4e14021 11 bytes [B8, 09, 5D, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!DeleteService + 1 00007ffac4e1a1a1 11 bytes [B8, 89, 59, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ffac4e1de41 11 bytes [B8, 49, 5B, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\rundll32.exe[1004] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ffac4e2ddf1 11 bytes [B8, 49, 54, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ffac721db10 12 bytes [48, B8, C9, 34, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!Process32NextW 00007ffac721e1f0 12 bytes [48, B8, 89, D0, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ffac72b34b1 11 bytes [B8, 89, 0F, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 1 00007ffac72daba1 8 bytes [B8, 09, E2, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 10 00007ffac72dabaa 2 bytes [50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ffac72daca1 11 bytes [B8, 49, E7, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CloseHandle 00007ffac48614c0 12 bytes [48, B8, 49, 4D, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary + 1 00007ffac48621d1 11 bytes [B8, 49, C4, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!GetProcAddress 00007ffac48642a0 12 bytes [48, B8, 09, C6, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!DeviceIoControl + 1 00007ffac4865f71 11 bytes [B8, 49, EE, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateMutexW 00007ffac4866ed0 12 bytes [48, B8, 89, 4B, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!OpenMutexW + 1 00007ffac4868a71 11 bytes [B8, C9, 49, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ffac4868d81 11 bytes [B8, 89, C2, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ffac48697b1 11 bytes [B8, C9, C0, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!FindFirstFileExW 00007ffac486c050 12 bytes [48, B8, 09, F0, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!FindNextFileW + 1 00007ffac486d781 11 bytes [B8, C9, F1, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ffac4872511 11 bytes [B8, 09, E9, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ffac487ef70 12 bytes [48, B8, 89, 28, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ffac4896b21 11 bytes [B8, 89, 3D, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 1 00007ffac48b93c1 8 bytes [B8, C9, E3, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 10 00007ffac48b93ca 2 bytes [50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ffac48da841 11 bytes [B8, 89, DE, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread 00007ffac48dac50 4 bytes [48, B8, C9, 3B]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread + 5 00007ffac48dac55 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ffac492f811 11 bytes [B8, 49, 70, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ffac492f891 11 bytes [B8, 09, 72, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleA 00007ffac4930340 12 bytes [48, B8, C9, 73, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleW 00007ffac4930570 12 bytes [48, B8, 89, 75, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread 00007ffac4940c80 4 bytes [48, B8, C9, 1F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread + 5 00007ffac4940c85 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!ShowWindow 00007ffac52611b0 6 bytes [48, B8, C9, A4, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!ShowWindow + 8 00007ffac52611b8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx 00007ffac5261210 6 bytes [48, B8, 89, 7C, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ffac5261218 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!GetMessageW 00007ffac5262670 12 bytes [48, B8, 09, 6B, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!PeekMessageW + 1 00007ffac5262991 11 bytes [B8, 89, 6E, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CallNextHookEx 00007ffac5262ef0 12 bytes [48, B8, C9, 7A, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!PostMessageW + 1 00007ffac52633f1 11 bytes [B8, C9, 14, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!GetMessageA + 1 00007ffac5266191 11 bytes [B8, 49, 69, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 1 00007ffac5266391 3 bytes [B8, 09, 1E]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 5 00007ffac5266395 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffac5266d90 7 bytes [48, B8, 49, A1, 83, 6A, 00]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CreateWindowExW + 10 00007ffac5266d9a 2 bytes [50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CreateWindowExA 00007ffac526ab30 7 bytes [48, B8, 09, A3, 83, 6A, 00]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CreateWindowExA + 10 00007ffac526ab3a 2 bytes [50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowTextW + 1 00007ffac526ce31 11 bytes [B8, 49, AF, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!PeekMessageA + 1 00007ffac526db41 11 bytes [B8, C9, 6C, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!UserClientDllInitialize + 1 00007ffac526dec1 11 bytes [B8, 09, 21, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowW + 1 00007ffac5270e61 3 bytes [B8, 49, CB]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowW + 5 00007ffac5270e65 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWinEventHook 00007ffac5277100 12 bytes [48, B8, 09, 3A, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ffac5283ab1 11 bytes [B8, 89, A6, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!PostMessageA + 1 00007ffac5285921 11 bytes [B8, 09, 13, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowExW + 1 00007ffac5287161 11 bytes [B8, 09, CD, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 1 00007ffac5287691 5 bytes [B8, 89, C9, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 9 00007ffac5287699 3 bytes [00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ffac52977a1 11 bytes [B8, 49, A8, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 1 00007ffac52c0f61 8 bytes [B8, 49, 1C, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 10 00007ffac52c0f6a 2 bytes [50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!MessageBoxExA + 1 00007ffac52e7d01 11 bytes [B8, 09, AA, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!MessageBoxExW + 1 00007ffac52e7d31 11 bytes [B8, C9, AB, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!SetWindowTextA + 1 00007ffac52f1021 11 bytes [B8, 89, AD, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\USER32.dll!FindWindowA + 1 00007ffac52f1471 11 bytes [B8, C9, C7, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\GDI32.dll!GdiDllInitialize + 465 00007ffac6bc4121 11 bytes [B8, C9, 22, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\GDI32.dll!NamedEscape + 1 00007ffac6c84d41 11 bytes [B8, 49, 03, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 1 00007ffac71514a1 5 bytes [B8, 49, F5, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 7 00007ffac71514a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 1 00007ffac7152041 5 bytes [B8, 09, 05, 84, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 7 00007ffac7152047 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 1 00007ffac7152061 5 bytes [B8, 49, 0A, 84, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 7 00007ffac7152067 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 1 00007ffac7152071 5 bytes [B8, 89, 08, 84, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 7 00007ffac7152077 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 1 00007ffac7152091 5 bytes [B8, 09, 0C, 84, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 7 00007ffac7152097 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 1 00007ffac71520a1 5 bytes [B8, C9, 06, 84, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 7 00007ffac71520a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 1 00007ffac7152201 5 bytes [B8, 89, F3, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 7 00007ffac7152207 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 1 00007ffac7180fa1 5 bytes [B8, 09, F7, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 7 00007ffac7180fa7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 1 00007ffac7180fb1 5 bytes [B8, C9, F8, 83, 6A]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 7 00007ffac7180fb7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA 00007ffac71add10 4 bytes [48, B8, C9, 65]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA + 5 00007ffac71add15 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW 00007ffac71adda0 4 bytes [48, B8, 89, 67]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW + 5 00007ffac71adda5 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ffac570bb11 11 bytes [B8, 49, 7E, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!closesocket 00007ffac4f11be0 12 bytes [48, B8, C9, B9, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!recv + 1 00007ffac4f12571 11 bytes [B8, C9, FF, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!WSASend + 1 00007ffac4f12d61 11 bytes [B8, 89, BB, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!WSARecv + 1 00007ffac4f12ff1 11 bytes [B8, 89, 01, 84, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!WSASocketW 00007ffac4f13880 12 bytes [48, B8, 09, B8, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!socket + 1 00007ffac4f13bd1 11 bytes [B8, 89, FA, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoW 00007ffac4f14230 12 bytes [48, B8, 09, 9C, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!connect 00007ffac4f15730 12 bytes [48, B8, 49, 62, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoExW 00007ffac4f187e0 12 bytes [48, B8, C9, 9D, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!send + 1 00007ffac4f242d1 11 bytes [B8, 49, B6, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!WSAConnect + 1 00007ffac4f26fe1 11 bytes [B8, 09, FE, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\system32\WS2_32.dll!gethostbyname + 1 00007ffac4f354b1 11 bytes [B8, 89, 9F, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ffac4df47a1 11 bytes [B8, 09, 5D, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceW 00007ffac4df4d10 12 bytes [48, B8, C9, 50, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceA 00007ffac4dfa830 12 bytes [48, B8, 09, 4F, 83, 6A, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!ControlService + 1 00007ffac4dfae11 11 bytes [B8, 09, 56, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ffac4dfed61 11 bytes [B8, 49, 54, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ffac4e14021 11 bytes [B8, 49, 5B, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!DeleteService + 1 00007ffac4e1a1a1 11 bytes [B8, C9, 57, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ffac4e1de41 11 bytes [B8, 89, 59, 83, 6A, 00, 00, ...]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[660] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ffac4e2ddf1 11 bytes [B8, 89, 52, 83, 6A, 00, 00, ...]
.text C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe[8176] C:\WINDOWS\system32\KERNEL32.DLL!UnhandledExceptionFilter + 1 00007ffac72e0cf1 5 bytes [B8, 30, 08, 15, 03]
.text C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe[8176] C:\WINDOWS\system32\KERNEL32.DLL!UnhandledExceptionFilter + 7 00007ffac72e0cf7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ffac721db10 12 bytes [48, B8, C9, 34, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!Process32NextW 00007ffac721e1f0 12 bytes [48, B8, 89, B4, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ffac72b34b1 11 bytes [B8, 89, F3, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 1 00007ffac72daba1 8 bytes [B8, 09, C6, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileExA + 10 00007ffac72dabaa 2 bytes [50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ffac72daca1 11 bytes [B8, 49, CB, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CloseHandle 00007ffac48614c0 12 bytes [48, B8, 49, 4D, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary + 1 00007ffac48621d1 11 bytes [B8, 49, A8, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!GetProcAddress 00007ffac48642a0 12 bytes [48, B8, 09, AA, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!DeviceIoControl + 1 00007ffac4865f71 11 bytes [B8, 49, D2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateMutexW 00007ffac4866ed0 12 bytes [48, B8, 89, 4B, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!OpenMutexW + 1 00007ffac4868a71 11 bytes [B8, C9, 49, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ffac4868d81 11 bytes [B8, 89, A6, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ffac48697b1 11 bytes [B8, C9, A4, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!FindFirstFileExW 00007ffac486c050 12 bytes [48, B8, 09, D4, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!FindNextFileW + 1 00007ffac486d781 11 bytes [B8, C9, D5, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ffac4872511 11 bytes [B8, 09, CD, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ffac487ef70 12 bytes [48, B8, 89, 28, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ffac4896b21 11 bytes [B8, 89, 3D, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 1 00007ffac48b93c1 8 bytes [B8, C9, C7, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileExW + 10 00007ffac48b93ca 2 bytes [50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ffac48da841 11 bytes [B8, 89, C2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread 00007ffac48dac50 4 bytes [48, B8, C9, 3B]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateThread + 5 00007ffac48dac55 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ffac492f811 11 bytes [B8, 49, 70, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ffac492f891 11 bytes [B8, 09, 72, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleA 00007ffac4930340 12 bytes [48, B8, C9, 73, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!ReadConsoleW 00007ffac4930570 12 bytes [48, B8, 89, 75, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread 00007ffac4940c80 4 bytes [48, B8, C9, 1F]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\KERNELBASE.dll!CreateRemoteThread + 5 00007ffac4940c85 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!ShowWindow 00007ffac52611b0 6 bytes [48, B8, C9, 88, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!ShowWindow + 8 00007ffac52611b8 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx 00007ffac5261210 6 bytes [48, B8, 89, 7C, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ffac5261218 4 bytes [00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!GetMessageW 00007ffac5262670 12 bytes [48, B8, 09, 6B, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!PeekMessageW + 1 00007ffac5262991 11 bytes [B8, 89, 6E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CallNextHookEx 00007ffac5262ef0 12 bytes [48, B8, C9, 7A, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!PostMessageW + 1 00007ffac52633f1 11 bytes [B8, C9, F8, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!GetMessageA + 1 00007ffac5266191 11 bytes [B8, 49, 69, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 1 00007ffac5266391 3 bytes [B8, 09, 1E]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW + 5 00007ffac5266395 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ffac5266d90 7 bytes [48, B8, 49, 85, 83, 6A, 00]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CreateWindowExW + 10 00007ffac5266d9a 2 bytes [50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CreateWindowExA 00007ffac526ab30 7 bytes [48, B8, 09, 87, 83, 6A, 00]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CreateWindowExA + 10 00007ffac526ab3a 2 bytes [50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowTextW + 1 00007ffac526ce31 11 bytes [B8, 49, 93, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!PeekMessageA + 1 00007ffac526db41 11 bytes [B8, C9, 6C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!UserClientDllInitialize + 1 00007ffac526dec1 11 bytes [B8, 09, 05, 84, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowW + 1 00007ffac5270e61 3 bytes [B8, 49, AF]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowW + 5 00007ffac5270e65 3 bytes [6A, 00, 00]
.text ... * 2
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWinEventHook 00007ffac5277100 12 bytes [48, B8, 09, 3A, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ffac5283ab1 11 bytes [B8, 89, 8A, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!PostMessageA + 1 00007ffac5285921 11 bytes [B8, 09, F7, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowExW + 1 00007ffac5287161 11 bytes [B8, 09, B1, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 1 00007ffac5287691 5 bytes [B8, 89, AD, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowExA + 9 00007ffac5287699 3 bytes [00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ffac52977a1 11 bytes [B8, 49, 8C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 1 00007ffac52c0f61 8 bytes [B8, 49, 1C, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA + 10 00007ffac52c0f6a 2 bytes [50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!MessageBoxExA + 1 00007ffac52e7d01 11 bytes [B8, 09, 8E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!MessageBoxExW + 1 00007ffac52e7d31 11 bytes [B8, C9, 8F, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!SetWindowTextA + 1 00007ffac52f1021 11 bytes [B8, 89, 91, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\USER32.dll!FindWindowA + 1 00007ffac52f1471 11 bytes [B8, C9, AB, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ffac570bb11 11 bytes [B8, 49, 7E, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 1 00007ffac71514a1 5 bytes [B8, 49, D9, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextW + 7 00007ffac71514a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 1 00007ffac7152041 5 bytes [B8, 09, E9, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptCreateHash + 7 00007ffac7152047 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 1 00007ffac7152061 5 bytes [B8, 49, EE, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptHashData + 7 00007ffac7152067 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 1 00007ffac7152071 5 bytes [B8, 89, EC, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptGetHashParam + 7 00007ffac7152077 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 1 00007ffac7152091 5 bytes [B8, 09, F0, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptImportKey + 7 00007ffac7152097 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 1 00007ffac71520a1 5 bytes [B8, C9, EA, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptExportKey + 7 00007ffac71520a7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 1 00007ffac7152201 5 bytes [B8, 89, D7, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptAcquireContextA + 7 00007ffac7152207 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 1 00007ffac7180fa1 5 bytes [B8, 09, DB, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptGenKey + 7 00007ffac7180fa7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 1 00007ffac7180fb1 5 bytes [B8, C9, DC, 83, 6A]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CryptEncrypt + 7 00007ffac7180fb7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA 00007ffac71add10 4 bytes [48, B8, C9, 65]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceA + 5 00007ffac71add15 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW 00007ffac71adda0 4 bytes [48, B8, 89, 67]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\ADVAPI32.dll!CreateServiceW + 5 00007ffac71adda5 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ffac4df47a1 11 bytes [B8, 09, 5D, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceW 00007ffac4df4d10 12 bytes [48, B8, C9, 50, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!OpenServiceA 00007ffac4dfa830 12 bytes [48, B8, 09, 4F, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!ControlService + 1 00007ffac4dfae11 11 bytes [B8, 09, 56, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ffac4dfed61 11 bytes [B8, 49, 54, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ffac4e14021 11 bytes [B8, 49, 5B, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!DeleteService + 1 00007ffac4e1a1a1 11 bytes [B8, C9, 57, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ffac4e1de41 11 bytes [B8, 89, 59, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ffac4e2ddf1 11 bytes [B8, 89, 52, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!closesocket 00007ffac4f11be0 12 bytes [48, B8, C9, 9D, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!recv + 1 00007ffac4f12571 11 bytes [B8, C9, E3, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!WSASend + 1 00007ffac4f12d61 11 bytes [B8, 89, 9F, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!WSARecv + 1 00007ffac4f12ff1 11 bytes [B8, 89, E5, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!WSASocketW 00007ffac4f13880 12 bytes [48, B8, 09, 9C, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!socket + 1 00007ffac4f13bd1 11 bytes [B8, 89, DE, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoW 00007ffac4f14230 12 bytes [48, B8, 09, 80, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!connect 00007ffac4f15730 12 bytes [48, B8, 49, 62, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!GetAddrInfoExW 00007ffac4f187e0 12 bytes [48, B8, C9, 81, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!send + 1 00007ffac4f242d1 11 bytes [B8, 49, 9A, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!WSAConnect + 1 00007ffac4f26fe1 11 bytes [B8, 09, E2, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\system32\WS2_32.dll!gethostbyname + 1 00007ffac4f354b1 11 bytes [B8, 89, 83, 83, 6A, 00, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQueryEx 00007ffac3da4420 12 bytes [48, B8, C9, C0, 83, 6A, 00, ...]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_UTF8 00007ffac3dc3cd0 4 bytes [48, B8, 09, BF]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_UTF8 + 5 00007ffac3dc3cd5 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_W 00007ffac3dc4350 4 bytes [48, B8, 49, BD]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_W + 5 00007ffac3dc4355 7 bytes [6A, 00, 00, 00, 00, 50, C3]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_A 00007ffac3dffd90 4 bytes [48, B8, 89, BB]
.text C:\Windows\System32\spool\drivers\x64\3\E_YATIH3E.EXE[2800] C:\WINDOWS\SYSTEM32\DNSAPI.dll!DnsQuery_A + 5 00007ffac3dffd95 7 bytes [6A, 00, 00, 00, 00, 50, C3] |