Code:
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ntdll.dll!NtLoadDriver 7C91DB6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ntdll.dll!NtLoadDriver + 4 7C91DB72 2 Bytes [4A, 5F] {DEC EDX; POP EDI}
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ntdll.dll!NtSuspendProcess 7C91E83A 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ntdll.dll!NtSuspendProcess + 4 7C91E83E 2 Bytes [38, 5F]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateFileA 7C801A24 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!VirtualProtect 7C801AD0 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 00EC0001
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!LoadLibraryA 7C801D77 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!GetStartupInfoA 7C801EEE 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!LoadResource 7C80A065 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!GetProcAddress 7C80AC28 6 Bytes JMP 5F550F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!LoadLibraryW 7C80ACD3 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateMutexA 7C80EB3F 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateRemoteThread 7C810626 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateRemoteThread + 4 7C81062A 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateThread 7C81082F 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateFileW 7C810976 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!GetCommandLineA 7C812C8D 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!TerminateThread 7C81CACB 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!GetVolumeInformationA 7C827052 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!DebugActiveProcess 7C859F0B 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] kernel32.dll!CreateToolhelp32Snapshot 7C8647B7 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!GetKeyState 77D1C505 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!ShowWindow 77D1D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!ShowWindow + 4 77D1D8A8 2 Bytes [7A, 5F] {JP 0x61}
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!GetAsyncKeyState 77D1E655 6 Bytes JMP 5F430F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!SetWindowsHookExW 77D2E4AF 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!SetWindowsHookExA 77D311E9 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!SetWinEventHook 77D317C8 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!GetWindowTextA 77D3213C 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!DdeConnect 77D57D7B 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!EndTask 77D59C5D 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!RegisterRawInputDevices 77D6C9C6 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] USER32.dll!RegisterRawInputDevices + 4 77D6C9CA 2 Bytes [53, 5F] {PUSH EBX; POP EDI}
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!RegOpenKeyExA 77DA761B 6 Bytes JMP 5F5E0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!RegCreateKeyExA 77DAEAF4 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!RegSetValueExA 77DAEBE7 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!OpenSCManagerA 77DBADA7 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!LsaRemoveAccountRights 77DEAA41 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1212] ADVAPI32.dll!CreateServiceA 77E07071 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtLoadDriver 7C91DB6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtLoadDriver + 4 7C91DB72 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtSuspendProcess 7C91E83A 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1232] ntdll.dll!NtSuspendProcess + 4 7C91E83E 2 Bytes [44, 5F] {INC ESP; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateFileA 7C801A24 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!VirtualProtect 7C801AD0 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 00E20001
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!LoadLibraryA 7C801D77 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!GetStartupInfoA 7C801EEE 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!LoadResource 7C80A065 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!GetProcAddress 7C80AC28 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!LoadLibraryW 7C80ACD3 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateMutexA 7C80EB3F 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateRemoteThread 7C810626 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateRemoteThread + 4 7C81062A 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateThread 7C81082F 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateFileW 7C810976 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!GetCommandLineA 7C812C8D 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!TerminateThread 7C81CACB 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!GetVolumeInformationA 7C827052 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!DebugActiveProcess 7C859F0B 6 Bytes JMP 5F490F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] kernel32.dll!CreateToolhelp32Snapshot 7C8647B7 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!RegOpenKeyExA 77DA761B 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!RegCreateKeyExA 77DAEAF4 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!RegSetValueExA 77DAEBE7 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!OpenSCManagerA 77DBADA7 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!LsaRemoveAccountRights 77DEAA41 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\svchost.exe[1232] ADVAPI32.dll!CreateServiceA 77E07071 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!GetKeyState 77D1C505 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!ShowWindow 77D1D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!ShowWindow + 4 77D1D8A8 2 Bytes [86, 5F]
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!GetAsyncKeyState 77D1E655 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!SetWindowsHookExW 77D2E4AF 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!SetWindowsHookExA 77D311E9 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!SetWinEventHook 77D317C8 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!GetWindowTextA 77D3213C 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!DdeConnect 77D57D7B 6 Bytes JMP 5F520F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!EndTask 77D59C5D 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!RegisterRawInputDevices 77D6C9C6 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1232] USER32.dll!RegisterRawInputDevices + 4 77D6C9CA 2 Bytes [5F, 5F] {POP EDI; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1232] SHELL32.dll!ShellExecuteExW 7CA1172B 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\svchost.exe[1232] SHELL32.dll!ShellExecuteEx 7CA50AED 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\svchost.exe[1232] SHELL32.dll!ShellExecuteA 7CA50E18 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\svchost.exe[1232] SHELL32.dll!ShellExecuteW 7CAC4A18 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtLoadDriver 7C91DB6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtLoadDriver + 4 7C91DB72 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtSuspendProcess 7C91E83A 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtSuspendProcess + 4 7C91E83E 2 Bytes [44, 5F] {INC ESP; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateFileA 7C801A24 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!VirtualProtect 7C801AD0 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F130F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes CALL 00C80001
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadLibraryA 7C801D77 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F190F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!GetStartupInfoA 7C801EEE 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadResource 7C80A065 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!GetProcAddress 7C80AC28 6 Bytes JMP 5F610F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadLibraryW 7C80ACD3 6 Bytes JMP 5F220F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateMutexA 7C80EB3F 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateRemoteThread 7C810626 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateRemoteThread + 4 7C81062A 2 Bytes [11, 5F]
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateThread 7C81082F 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateFileW 7C810976 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!GetCommandLineA 7C812C8D 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!TerminateThread 7C81CACB 6 Bytes JMP 5F460F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!GetVolumeInformationA 7C827052 6 Bytes JMP 5F640F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!DebugActiveProcess 7C859F0B 6 Bytes JMP 5F490F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!WinExec 7C86114D 6 Bytes JMP 5F3D0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!CreateToolhelp32Snapshot 7C8647B7 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!RegOpenKeyExA 77DA761B 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!RegCreateKeyExA 77DAEAF4 6 Bytes JMP 5F670F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!RegSetValueExA 77DAEBE7 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!OpenSCManagerA 77DBADA7 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!LsaRemoveAccountRights 77DEAA41 6 Bytes JMP 5F160F5A
.text C:\WINDOWS\system32\svchost.exe[1300] ADVAPI32.dll!CreateServiceA 77E07071 6 Bytes JMP 5F580F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!GetKeyState 77D1C505 6 Bytes JMP 5F4C0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!ShowWindow 77D1D8A4 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!ShowWindow + 4 77D1D8A8 2 Bytes [86, 5F]
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!GetAsyncKeyState 77D1E655 6 Bytes JMP 5F4F0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!SetWindowsHookExW 77D2E4AF 6 Bytes JMP 5F280F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!SetWindowsHookExA 77D311E9 6 Bytes JMP 5F250F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!SetWinEventHook 77D317C8 6 Bytes JMP 5F5B0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!GetWindowTextA 77D3213C 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!DdeConnect 77D57D7B 6 Bytes JMP 5F520F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!EndTask 77D59C5D 6 Bytes JMP 5F400F5A
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!RegisterRawInputDevices 77D6C9C6 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] USER32.dll!RegisterRawInputDevices + 4 77D6C9CA 2 Bytes [5F, 5F] {POP EDI; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1300] SHELL32.dll!ShellExecuteExW 7CA1172B 6 Bytes JMP 5F3A0F5A
.text C:\WINDOWS\system32\svchost.exe[1300] SHELL32.dll!ShellExecuteEx 7CA50AED 6 Bytes JMP 5F370F5A
.text C:\WINDOWS\system32\svchost.exe[1300] SHELL32.dll!ShellExecuteA 7CA50E18 6 Bytes JMP 5F310F5A
.text C:\WINDOWS\system32\svchost.exe[1300] SHELL32.dll!ShellExecuteW 7CAC4A18 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtLoadDriver 7C91DB6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtLoadDriver + 4 7C91DB72 2 Bytes [56, 5F] {PUSH ESI; POP EDI}
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtSuspendProcess 7C91E83A 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtSuspendProcess + 4 7C91E83E 2 Bytes [44, 5F] {INC ESP; POP EDI}
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileA 7C801A24 6 Bytes JMP 5F730F5A |