GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-04-27 15:56:09
Windows 5.1.2600 Service Pack 2
——System - GMER 1.0.14——
SSDT \??\C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xF711F8AC]
SSDT \??\C:\Programmer\SUPERAntiSpyware\SASKUTIL.sys ZwTerminateProcess [0xAC954660]
——User code sections - GMER 1.0.14——
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!StrStrW + FFE25BCA 7C9C217D 272 Bytes [ C1, F1, 77, 48, A2, F1, 77, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!StrStrW + FFE25CDB 7C9C228E 1 Byte [ 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!StrStrW + FFE25CDD 7C9C2290 117 Bytes [ E7, 30, 83, 7C, 27, F8, 82, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!StrStrW + FFE25D53 7C9C2306 90 Bytes [ 81, 7C, F7, 28, 83, 7C, 5D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!StrStrW + FFE25DAE 7C9C2361 2 Bytes [ 30, 81 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDiskFreeSpaceExW + 9B 7C9EA8DC 63 Bytes [ 53, 48, 47, 65, 74, 44, 69, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDiskFreeSpaceExW + DB 7C9EA91C 149 Bytes [ 53, 48, 47, 65, 74, 46, 69, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDiskFreeSpaceExW + 171 7C9EA9B2 610 Bytes [ 53, 48, 47, 65, 74, 49, 63, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFree + 3B 7C9EAC15 344 Bytes [ 64, 49, 6E, 50, 72, 6F, 63, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFree + 194 7C9EAD6E 235 Bytes [ 53, 48, 51, 75, 65, 72, 79, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFree + 7E 7C9EAE5A 18 Bytes [ 6F, 67, 57, 00, 53, 48, 54, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFree + 91 7C9EAE6D 796 Bytes [ 65, 72, 73, 68, 69, 70, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILClone + A5 7C9EB18A 409 Bytes [ 57, 00, 53, 74, 72, 4E, 43, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILClone + 23F 7C9EB324 8 Bytes [ 55, 8B, EC, FF, 75, 08, 6A, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILClone + 248 7C9EB32D 37 Bytes [ 15, 28, 16, 9C, 7C, 5D, C3, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILClone + 26E 7C9EB353 118 Bytes [ 8C, 03, 00, 8B, C7, 5F, 5E, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCloneFirst + 79 7C9EB3CD 14 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCloneFirst + 88 7C9EB3DC 41 Bytes [ 5D, 08, 56, 57, 53, 89, 45, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCombine + 1 7C9EB406 56 Bytes CALL 7C9E83FE C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCombine + 3A 7C9EB43F 15 Bytes [ 8B, BA, 06, 00, 85, FF, 74, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCombine + 4A 7C9EB44F 57 Bytes [ 4D, FC, 8B, C7, 5F, 5E, 5B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCombine + 84 7C9EB489 44 Bytes [ 5D, 08, 8D, 34, 9D, A8, F6, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCombine + B1 7C9EB4B6 28 Bytes [ 90, 90, 90, 90, 90, 81, C1, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDesktopFolder + 13 7C9EBA6B 44 Bytes [ 3B, D7, 72, 1A, 77, 04, 3B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDesktopFolder + 40 7C9EBA98 25 Bytes [ 5E, 5B, C9, C2, 10, 00, 90, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDesktopFolder + 5A 7C9EBAB2 24 Bytes [ 15, 60, 15, 9C, 7C, 8B, F8, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDesktopFolder + 73 7C9EBACB 44 Bytes [ C7, 5F, 5E, 5D, C2, 04, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetDesktopFolder + A0 7C9EBAF8 233 Bytes [ 90, 90, 90, 90, 90, C7, 01, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHRestricted + 38 7C9EC381 38 Bytes [ 85, C0, 74, 1E, 56, 8B, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHRestricted + 5F 7C9EC3A8 2 Bytes [ 90, 90 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHRestricted + 63 7C9EC3AC 10 Bytes [ 90, 8B, FF, 55, 8B, EC, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHRestricted + 6F 7C9EC3B8 41 Bytes [ 83, C0, 04, 50, FF, 75, 08, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHRestricted + 99 7C9EC3E2 35 Bytes [ 4D, 08, 56, 8B, F1, 57, C1, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILRemoveLastID + 1 7C9EC4A8 4 Bytes [ EC, 83, EC, 10 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILRemoveLastID + 8 7C9EC4AF 28 Bytes [ 85, C9, 0F, 85, 06, 07, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILRemoveLastID + 25 7C9EC4CC 93 Bytes [ 8B, C1, 8D, 50, 04, C7, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILRemoveLastID + 83 7C9EC52A 104 Bytes [ F8, 7F, 05, 0E, 00, 07, 80, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILRemoveLastID + EC 7C9EC593 6 Bytes [ 80, 0F, 8D, 4E, 7E, 00 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetSettings + 63 7C9EC703 75 Bytes [ 50, A5, 89, 45, C8, FF, 15, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetSettings + AF 7C9EC74F 42 Bytes [ 74, 17, FF, 75, CC, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetSettings + DA 7C9EC77A 27 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetSettings + F6 7C9EC796 78 Bytes [ 0F, 8C, E4, 01, 00, 00, 56, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetSettings + 145 7C9EC7E5 5 Bytes [ 56, 57, 68, D0, 00 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCLSIDFromString + 26 7C9ECAC9 28 Bytes [ 55, 8B, EC, 8B, 45, 08, 53, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCLSIDFromString + 43 7C9ECAE6 96 Bytes [ D8, 0F, 84, 8E, E4, 06, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCLSIDFromString + A4 7C9ECB47 39 Bytes [ 47, 85, C0, 74, 49, 8B, 08, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCLSIDFromString + CC 7C9ECB6F 62 Bytes [ 11, 85, C0, 7C, 18, 56, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCLSIDFromString + 10B 7C9ECBAE 8 Bytes [ FF, 75, 10, FF, 75, 08, E8, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindLastID + 2A 7C9ECC96 80 Bytes [ 53, FF, 75, 10, 8D, 4F, F0, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindLastID + 7B 7C9ECCE7 53 Bytes [ CE, 2B, C8, D1, F9, 51, 50, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindLastID + B1 7C9ECD1D 114 Bytes [ 75, 10, 53, FF, 37, FF, 15, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindLastID + 124 7C9ECD90 55 Bytes [ 49, 00, 44, 00, 50, 00, 52, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindLastID + 15C 7C9ECDC8 7 Bytes [ 69, 00, 43, 00, 61, 00, 63 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHParseDisplayName + 3E 7C9EDE9E 133 Bytes [ 0F, 84, 0C, 85, 03, 00, 83, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHParseDisplayName + C4 7C9EDF24 57 Bytes [ EC, 51, 51, 53, 56, 57, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHParseDisplayName + FF 7C9EDF5F 51 Bytes CALL 7C9EDE03 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHParseDisplayName + 133 7C9EDF93 11 Bytes [ 55, 8B, EC, 83, EC, 18, A1, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHParseDisplayName + 13F 7C9EDF9F 29 Bytes [ 56, 8B, F1, 89, 45, FC, 8B, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHILCreateFromPath + 8C 7C9EE4BC 27 Bytes CALL 7C9EE461 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHILCreateFromPath + A8 7C9EE4D8 46 Bytes [ 00, 00, 8B, D8, 8B, 4D, FC, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHILCreateFromPath + D8 7C9EE508 33 Bytes [ 8B, 45, 14, 53, 8B, 5D, 08, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHILCreateFromPath + FA 7C9EE52A 89 Bytes [ 8D, BD, E4, FB, FF, FF, F3, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHILCreateFromPath + 154 7C9EE584 19 Bytes [ 53, FF, 75, 14, 57, 50, FF, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCreateFromPath + 1 7C9EE5D0 8 Bytes [ EC, FF, 75, 10, FF, 75, 0C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCreateFromPath + A 7C9EE5D9 13 Bytes [ 68, 90, 44, 9C, 7C, 6A, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCreateFromPath + 18 7C9EE5E7 7 Bytes [ FF, 5D, C2, 0C, 00, 90, 90 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCreateFromPath + 22 7C9EE5F1 6 Bytes [ 8B, FF, 55, 8B, EC, 81 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILCreateFromPath + 29 7C9EE5F8 52 Bytes [ 30, 02, 00, 00, A1, 48, F5, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathW + 14 7C9EF066 49 Bytes [ 8B, D8, 85, DB, 7C, 6B, 83, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathW + 46 7C9EF098 10 Bytes [ C8, 8B, 45, CC, 8B, 08, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathW + 51 7C9EF0A3 41 Bytes [ 55, C0, 52, 56, 57, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathW + 7B 7C9EF0CD 5 Bytes [ FF, 8B, 45, CC, 8B ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathW + 81 7C9EF0D3 35 Bytes [ 50, FF, 51, 08, 8B, 4D, FC, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderLocation + D 7C9EF54A 8 Bytes [ 57, 6A, 2C, 89, 45, FC, BF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderLocation + 16 7C9EF553 13 Bytes [ 07, 80, 8B, C3, 59, 90, 90, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderLocation + 24 7C9EF561 20 Bytes [ 00, 00, 40, 49, 75, F9, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderLocation + 39 7C9EF576 17 Bytes CALL 7C9ECB3A C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderLocation + 4B 7C9EF588 33 Bytes [ 66, C7, 03, 19, 00, C6, 43, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderLocation 7C9EF5BF 9 Bytes [ 68, 30, 81, 9C, 7C, E8, 06, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderLocation + A 7C9EF5C9 188 Bytes [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderLocation + C7 7C9EF686 29 Bytes [ 15, 30, 10, 9C, 7C, 85, C0, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderLocation + E5 7C9EF6A4 59 Bytes [ 85, C0, 75, 2F, 8D, 45, AC, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderLocation + 121 7C9EF6E0 21 Bytes [ 8B, 4D, FC, 8B, 45, A8, 5F, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCoCreateInstance + 65 7C9EF927 8 Bytes [ 33, C0, 8D, 7D, F4, AB, AB, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCoCreateInstance + 6E 7C9EF930 36 Bytes [ 06, 8D, 55, F0, 52, C7, 45, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCoCreateInstance + 93 7C9EF955 29 Bytes [ 08, 5E, 8B, 45, 08, 5F, 5B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCoCreateInstance + B1 7C9EF973 22 Bytes [ 8D, 7A, 08, C7, 02, AC, 81, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCoCreateInstance + CB 7C9EF98D 58 Bytes [ 90, 8B, FF, 55, 8B, EC, 56, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetClassObject + 1C 7C9EFA95 8 Bytes [ 8B, 8D, A0, FD, FF, FF, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetClassObject + 25 7C9EFA9E 49 Bytes [ FD, FF, FF, 50, FF, 33, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetClassObject + 57 7C9EFAD0 19 Bytes CALL 7C9E83AC C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetClassObject + 6B 7C9EFAE4 23 Bytes [ B5, A8, FD, FF, FF, 6A, 0B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetClassObject + 84 7C9EFAFD 63 Bytes [ 50, F3, A5, FF, 15, 3C, 1C, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHBindToParent + 2 7C9EFD21 35 Bytes [ 00, 56, 89, 45, FC, 8B, 45, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHBindToParent + 26 7C9EFD45 63 Bytes [ 8D, 85, F4, FD, FF, FF, 51, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHBindToParent + 66 7C9EFD85 57 Bytes [ 00, 85, C0, 0F, 85, 69, 0C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHBindToParent + A0 7C9EFDBF 35 Bytes CALL 7C9EDE88 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHBindToParent + C4 7C9EFDE3 63 Bytes [ EC, 83, EC, 20, 56, 8B, F1, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsNetDrive + 69 7C9F0E39 50 Bytes [ 7F, 0F, 87, 6D, 2B, 05, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsNetDrive + 9C 7C9F0E6C 192 Bytes [ 56, 57, FF, 75, 14, 8B, 7D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsNetDrive + 15D 7C9F0F2D 21 Bytes [ 50, 1C, 85, C0, 5F, 0F, 8C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsNetDrive + 173 7C9F0F43 69 Bytes [ 15, D4, 15, 9C, 7C, 8B, 4D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsNetDrive + 1B9 7C9F0F89 17 Bytes CALL 7C9F08AD C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DriveType + 13 7C9F1675 5 Bytes [ 00, 00, 02, 6A, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DriveType + 19 7C9F167B 18 Bytes [ 75, 0C, FF, 75, 08, FF, 15, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DriveType + 2C 7C9F168E 31 Bytes [ 8B, 45, 0C, 5D, C2, 08, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DriveType + 4C 7C9F16AE 27 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DriveType + 68 7C9F16CA 28 Bytes [ 75, 0C, FF, 75, 08, FF, 50, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetPathFromIDListW + 3B 7C9F17F3 17 Bytes JMP 7C9EB4A3 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetPathFromIDListW + 4D 7C9F1805 18 Bytes [ 56, 8B, 75, 08, 57, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetPathFromIDListW + 60 7C9F1818 25 Bytes [ 75, 14, 8B, D8, 8B, CF, 89, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetPathFromIDListW + 7A 7C9F1832 47 Bytes [ 00, 49, 0F, 85, FD, 3D, 01, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetPathFromIDListW + AA 7C9F1862 10 Bytes [ 85, DB, 8B, C3, 0F, 85, 13, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsEqual + 20 7C9F19C3 7 Bytes [ C3, 5B, 5D, C2, 10, 00, FF ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsEqual + 28 7C9F19CB 26 Bytes [ 14, 8B, 76, 18, FF, 75, 10, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsEqual + 43 7C9F19E6 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsEqual + 46 7C9F19E9 52 Bytes [ EC, 81, EC, 54, 04, 00, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsEqual + 7B 7C9F1A1E 1 Byte [ FD ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderPathW + 11 7C9F1B4C 13 Bytes [ FF, FF, 85, C0, 74, C9, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderPathW + 1F 7C9F1B5A 9 Bytes [ 85, C0, FF, 75, 0C, 0F, 84, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderPathW + 29 7C9F1B64 23 Bytes CALL 7C9EDC4A C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderPathW + 42 7C9F1B7D 8 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSpecialFolderPathW + 4B 7C9F1B86 5 Bytes [ EC, 81, EC, 84, 01 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsSlowW + 24 7C9F1BC7 11 Bytes [ 0F, 84, C8, 00, 00, 00, 85, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsSlowW + 32 7C9F1BD5 4 Bytes [ B9, FF, FF, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsSlowW + 37 7C9F1BDA 93 Bytes [ 85, 4D, 0C, 0F, 85, 4B, 4B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsSlowW + 95 7C9F1C38 4 Bytes [ 8D, B5, 9C, FE ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsSlowW + 9B 7C9F1C3E 187 Bytes [ 33, C0, F3, A6, 0F, 85, 1D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsParent + 91 7C9F1CFA 9 Bytes [ 66, 39, 1E, 0F, 84, 10, C8, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILIsParent + 9B 7C9F1D04 47 Bytes CALL 7C9EC354 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindChild + B 7C9F1D34 25 Bytes [ 08, 8D, 55, 08, 52, 68, 74, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindChild + 25 7C9F1D4E 47 Bytes [ 50, FF, 51, 08, 8B, 45, 14, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindChild + 55 7C9F1D7E 26 Bytes [ 1B, C0, 83, D8, FF, E9, C5, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindChild + 70 7C9F1D99 4 Bytes CALL 7C9F36B9 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILFindChild + 75 7C9F1D9E 19 Bytes CALL 089F1D9E
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyDeregister + 2 7C9F58C0 66 Bytes [ C9, C2, 04, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyDeregister + 45 7C9F5903 53 Bytes [ 5F, 5E, C9, C2, 10, 00, 90, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyDeregister + 7B 7C9F5939 1 Byte [ 1C ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyDeregister + 7F 7C9F593D 61 Bytes [ 85, C0, 0F, 84, E6, 91, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyDeregister + BD 7C9F597B 14 Bytes [ 75, 18, 5F, 89, 45, FC, 6A, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetImageLists + 36 7C9F62C6 9 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetImageLists + 40 7C9F62D0 2 Bytes [ 4D, 0C ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetImageLists + 43 7C9F62D3 150 Bytes [ B8, 03, 04, 00, 00, 33, F6, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetImageLists + DA 7C9F636A 30 Bytes [ 8B, 0D, A0, F5, BC, 7C, E8, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetImageLists + F9 7C9F6389 75 Bytes [ 79, 04, 3B, C7, 0F, 85, D7, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetCachedImageIndex + 2 7C9F6557 43 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetCachedImageIndex + 2E 7C9F6583 3 Bytes [ EC, 51, 8D ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetCachedImageIndex + 32 7C9F6587 6 Bytes [ FC, 50, 8D, 45, 08, 50 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetCachedImageIndex + 39 7C9F658E 9 Bytes CALL 7C9F63FB C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_GetCachedImageIndex + 43 7C9F6598 197 Bytes [ C0, 0F, 8C, 97, 72, 00, 00, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyRegister + 3B 7C9F733A 2 Bytes [ 8B, F8 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyRegister + 3E 7C9F733D 22 Bytes [ 45, 0C, 8B, 08, 50, FF, 51, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyRegister + 55 7C9F7354 21 Bytes [ FF, 90, 90, 90, 61, 63, 9F, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyRegister + 6B 7C9F736A 31 Bytes [ BD, 7C, FF, 0F, 84, BA, AF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotifyRegister + 8B 7C9F738A 7 Bytes [ 55, 8B, EC, 83, 7D, 08, 00 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_MergeMenus + B 7C9F7A07 67 Bytes [ 00, 8B, 85, 98, F9, FF, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_MergeMenus + 4F 7C9F7A4B 48 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_MergeMenus + 80 7C9F7A7C 31 Bytes [ 85, C0, 75, 0D, FF, 75, 0C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_MergeMenus + A3 7C9F7A9F 46 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_MergeMenus + D2 7C9F7ACE 13 Bytes CALL 7C9F65E7 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateShellFolderView + 2 7C9F9064 37 Bytes [ 75, 08, 8D, 8E, 40, 02, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateShellFolderView + 28 7C9F908A 50 Bytes [ 6A, 00, 6A, 00, 68, BB, 04, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateShellFolderView + 5B 7C9F90BD 62 Bytes [ 00, 00, 85, C0, 0F, 84, 02, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateShellFolderView + 9A 7C9F90FC 130 Bytes [ 00, FF, 75, 08, 8B, 00, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateShellFolderView + 11D 7C9F917F 5 Bytes [ 80, A6, 12, 02, 00 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapIDListToImageListIndexAsync + 38 7C9FB5A4 27 Bytes [ 8D, 88, 00, 8E, FF, FF, 81, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapIDListToImageListIndexAsync + 54 7C9FB5C0 6 Bytes [ 00, 6A, 0A, EB, 3F, 6A ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapIDListToImageListIndexAsync + 5B 7C9FB5C7 83 Bytes [ 8D, 8D, F0, FE, FF, FF, 51, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapIDListToImageListIndexAsync + AF 7C9FB61B 7 Bytes [ FF, 51, 57, FF, B5, F8, FE ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapIDListToImageListIndexAsync + B7 7C9FB623 61 Bytes [ FF, 6A, 2B, 83, A5, F0, FE, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 12 7C9FC29E 3 Bytes [ 8B, 7D, 08 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 18 7C9FC2A4 68 Bytes [ 8B, F1, 8B, 86, 48, 01, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 5D 7C9FC2E9 23 Bytes [ FF, 55, 8B, EC, 81, EC, 54, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 75 7C9FC301 46 Bytes [ 75, 14, 89, 85, C0, F9, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHMapPIDLToSystemImageListIndex + A4 7C9FC330 99 Bytes CALL 7C9EDA4F C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetImageList 7C9FE4A9 33 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetImageList + 22 7C9FE4CB 11 Bytes [ F0, 85, F6, 7C, 1A, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetImageList + 2F 7C9FE4D8 4 Bytes [ 0C, 8B, 08, 50 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetImageList + 34 7C9FE4DD 1 Byte [ 51 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetImageList + 36 7C9FE4DF 118 Bytes [ 8B, F0, 8B, 45, 08, 8B, 08, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHExtractIconsW + 10 7C9FE914 15 Bytes [ 00, A1, 48, F5, BC, 7C, 56, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHExtractIconsW + 21 7C9FE925 16 Bytes CALL 8C9FE925
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHExtractIconsW + 32 7C9FE936 24 Bytes [ 76, 38, BB, 84, 10, 9D, 7C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHExtractIconsW + 4C 7C9FE950 9 Bytes [ 83, C4, 10, 85, C0, 7C, 2E, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHExtractIconsW + 56 7C9FE95A 16 Bytes [ FB, FF, FF, 50, 68, 02, 00, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetVersion 7C9FF5BB 5 Bytes [ 90, 90, 8B, FF, 55 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetVersion + 6 7C9FF5C1 6 Bytes [ EC, 81, EC, 28, 02, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetVersion + D 7C9FF5C8 77 Bytes [ A1, 48, F5, BC, 7C, 89, 45, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetVersion + 5B 7C9FF616 43 Bytes [ 15, 04, 16, 9C, 7C, 39, 35, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllGetVersion + 87 7C9FF642 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathResolve + 5B 7CA0212D 338 Bytes [ B9, 89, 7A, AD, 7C, 89, 15, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathResolve + 1AE 7CA02280 2 Bytes [ D1, 5D ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathResolve + 1B2 7CA02284 17 Bytes [ 34, 4B, 17, 9B, FF, 40, D2, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathResolve + 1C4 7CA02296 20 Bytes [ 00, 00, 80, 54, 27, F2, 82, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathResolve + 1DA 7CA022AC 19 Bytes [ 83, 25, A0, 00, BD, 7C, 00, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ShellExecuteExW + 96 7CA025D1 61 Bytes [ 83, FF, 08, 0F, 8E, E1, 8E, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ShellExecuteExW + D4 7CA0260F 33 Bytes [ 8B, 75, 08, 3B, F3, 75, 0C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ShellExecuteExW + F6 7CA02631 92 Bytes [ 10, 89, 91, AC, 00, BD, 7C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ShellExecuteExW + 153 7CA0268E 62 Bytes [ 00, 56, FF, 35, 84, 05, BD, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ShellExecuteExW + 192 7CA026CD 30 Bytes [ 1D, 9C, 7C, 99, 2B, C2, D1, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHTestTokenMembership + 4D 7CA04BE8 6 Bytes [ F1, 8B, 86, 30, 60, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHTestTokenMembership + 54 7CA04BEF 18 Bytes [ 8B, 08, 68, 48, 10, 00, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHTestTokenMembership + 68 7CA04C03 15 Bytes [ 6A, 01, 6A, 00, 50, FF, 51, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHTestTokenMembership + 78 7CA04C13 28 Bytes [ 5F, 5E, 8B, C3, 5B, 5D, C2, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHTestTokenMembership + 95 7CA04C30 96 Bytes [ C0, 0F, 85, 9C, 9C, 04, 00, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!OpenRegStream + 3D 7CA05137 71 Bytes [ 00, 00, 56, 8D, 70, 04, 56, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!OpenRegStream + 85 7CA0517F 3 Bytes [ 00, 00, 8D ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!OpenRegStream + 89 7CA05183 5 Bytes [ A4, FD, FF, FF, 50 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!OpenRegStream + 8F 7CA05189 3 Bytes [ 85, AC, FD ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!OpenRegStream + 93 7CA0518D 16 Bytes CALL 7C9EF8D1 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILLoadFromStream + 4 7CA05F76 58 Bytes [ D8, 85, DB, 0F, 8C, 5B, C1, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILLoadFromStream + 3F 7CA05FB1 31 Bytes CALL 7C9E83AE C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILLoadFromStream + 5F 7CA05FD1 25 Bytes [ 5D, C2, 04, 00, 48, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILLoadFromStream + 79 7CA05FEB 224 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ILLoadFromStream + 15A 7CA060CC 81 Bytes [ 15, B8, 10, 9C, 7C, 85, C0, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DAD_ShowDragImage + 1 7CA082DD 114 Bytes [ 47, 30, 85, C0, 0F, 85, 12, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DAD_ShowDragImage + 74 7CA08350 2 Bytes [ 50, 53 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DAD_ShowDragImage + 77 7CA08353 3 Bytes [ CE, F9, FF ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DAD_ShowDragImage + 7B 7CA08357 43 Bytes [ 8B, 06, F7, D8, 1B, C0, 25, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DAD_ShowDragImage + A7 7CA08383 190 Bytes [ FF, 15, EC, 14, 9C, 7C, 85, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathAndSubDirW + F 7CA0A817 5 Bytes [ FF, 01, 00, 00, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetFolderPathAndSubDirW + 15 7CA0A81D 131 Bytes [ B5, F8, FD, FF, FF, FF, 15, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateDirectoryExW + 17 7CA0A8A1 99 Bytes [ 16, 9C, 7C, 5F, 5E, 5B, C3, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateDirectoryExW + 7B 7CA0A905 23 Bytes [ 85, C0, 7C, 23, 8B, 46, 10, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateDirectoryExW + 93 7CA0A91D 84 Bytes [ 46, 30, 68, 55, 04, 00, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateDirectoryExW + E8 7CA0A972 4 Bytes [ 84, B6, F0, 04 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCreateDirectoryExW + ED 7CA0A977 3 Bytes [ 6A, 43, FF ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHUpdateRecycleBinIcon + 5 7CA0B325 39 Bytes [ 8B, C6, 5E, 5D, C2, 04, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHUpdateRecycleBinIcon + 2D 7CA0B34D 49 Bytes [ BD, 7C, 3B, 18, 75, E0, 33, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHUpdateRecycleBinIcon + 5F 7CA0B37F 93 Bytes JMP 7C9F7B71 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHUpdateRecycleBinIcon + BD 7CA0B3DD 49 Bytes [ FF, 8B, F0, 3B, F7, 0F, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHUpdateRecycleBinIcon + EF 7CA0B40F 69 Bytes [ FF, 75, FC, FF, 56, 18, E9, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsUserAnAdmin + 35 7CA0D1D0 16 Bytes [ 07, 77, 03, 8B, 45, 08, 5D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsUserAnAdmin + 46 7CA0D1E1 19 Bytes [ 55, 8B, EC, 83, 7D, 0C, 01, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsUserAnAdmin + 5A 7CA0D1F5 5 Bytes [ 0F, 85, 72, CB, 03 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsUserAnAdmin + 60 7CA0D1FB 42 Bytes [ 53, 8B, 5D, 14, 56, 8B, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!IsUserAnAdmin + 8B 7CA0D226 16 Bytes [ 4D, CB, 03, 00, 8B, 45, 10, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathProcessCommand + 41 7CA0DB0C 1 Byte [ 53 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathProcessCommand + 43 7CA0DB0E 38 Bytes [ B5, D0, FB, FF, FF, 8D, 85, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathProcessCommand + 6A 7CA0DB35 9 Bytes [ FF, 83, FE, FF, 0F, 84, 36, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathProcessCommand + 74 7CA0DB3F 22 Bytes [ FF, 85, D0, FB, FF, FF, 83, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathProcessCommand + 8B 7CA0DB56 5 Bytes [ 89, 9D, B0, FB, FF ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileW + 13 7CA10F1D 17 Bytes [ 39, B5, CC, FD, FF, FF, 0F, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileAorW + 2 7CA10F2F 37 Bytes [ 03, 45, 14, 3B, 45, 18, 89, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileAorW + 28 7CA10F55 48 Bytes [ 15, 7C, 1F, 9C, 7C, 85, C0, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileAorW + 5A 7CA10F87 61 Bytes [ 50, FF, B5, 54, FF, FF, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileAorW + 99 7CA10FC6 34 Bytes [ FF, FF, 85, 54, FF, FF, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DragQueryFileAorW + BC 7CA10FE9 30 Bytes [ 89, 45, FC, 8B, 45, 0C, 53, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!InternalExtractIconListA + 15 7CA1AF76 5 Bytes [ 33, C8, 89, 8B, A4 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!InternalExtractIconListA + 1C 7CA1AF7D 46 Bytes JMP 7CA1B413 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!InternalExtractIconListA + 4B 7CA1AFAC 39 Bytes [ 85, C0, 0F, 85, 60, 04, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!InternalExtractIconListA + 73 7CA1AFD4 5 Bytes [ 89, 83, A4, 00, 00 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!InternalExtractIconListA + 79 7CA1AFDA 58 Bytes JMP 7CA1B414 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetFolderCustomSettingsW + 53 7CA1D260 68 Bytes [ 76, 08, FF, D7, 85, C0, 74, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetFolderCustomSettingsW + 98 7CA1D2A5 25 Bytes [ 00, FF, 45, E4, 8B, 45, E4, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetFolderCustomSettingsW + B2 7CA1D2BF 34 Bytes [ F6, D9, 1B, C9, 23, 4D, 08, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetFolderCustomSettingsW + D5 7CA1D2E2 14 Bytes CALL 7CA18E03 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHGetSetFolderCustomSettingsW + E5 7CA1D2F2 43 Bytes [ F6, 46, 44, 01, 0F, 85, 67, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHSetLocalizedName + 6 7CA20C92 8 Bytes [ 6C, 24, 04, 08, E9, D2, F5, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHSetLocalizedName + F 7CA20C9B 28 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHSetLocalizedName + 2D 7CA20CB9 28 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHSetLocalizedName + 4B 7CA20CD7 57 Bytes [ F6, C3, 03, 74, 12, FF, 75, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHSetLocalizedName + 85 7CA20D11 14 Bytes JMP 7CA0EB33 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFlushSFCache + 77 7CA20E35 14 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFlushSFCache + 86 7CA20E44 29 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFlushSFCache + A4 7CA20E62 85 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFlushSFCache + FA 7CA20EB8 102 Bytes [ 33, C0, 89, 9D, DC, FD, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHFlushSFCache + 161 7CA20F1F 4 Bytes [ FD, FF, FF, 8D ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_NotifyIcon + B 7CA21821 45 Bytes [ 83, BD, 3C, F5, FF, FF, 01, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_NotifyIcon + 39 7CA2184F 7 Bytes [ FF, 00, 09, 8D, 28, F5, FF ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_NotifyIcon + 41 7CA21857 18 Bytes [ 89, 85, 58, F5, FF, FF, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_NotifyIcon + 54 7CA2186A 8 Bytes [ FF, 8B, F8, 85, FF, 7C, 23, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!Shell_NotifyIcon + 5D 7CA21873 2 Bytes [ 24, F5 ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Lock + 6 7CA21F23 70 Bytes [ 85, C0, 57, 8D, 85, F4, FD, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Lock + 4D 7CA21F6A 21 Bytes [ 00, FF, B5, BC, F9, FF, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Lock + 63 7CA21F80 21 Bytes CALL 7C9E83AC C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Lock + 79 7CA21F96 5 Bytes [ EC, 81, EC, 0C, 02 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Lock + 80 7CA21F9D 63 Bytes [ A1, 48, F5, BC, 7C, 8B, 4D, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractVersionResource16W + 73 7CA222EC 61 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractVersionResource16W + B2 7CA2232B 8 Bytes [ 75, F8, EB, F3, 90, 53, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractVersionResource16W + BB 7CA22334 1 Byte [ 46 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractVersionResource16W + BD 7CA22336 9 Bytes [ 54, 00, 57, 00, 41, 00, 52, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractVersionResource16W + C7 7CA22340 1 Byte [ 5C ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllCanUnloadNow + 27 7CA22EEC 15 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllCanUnloadNow + 37 7CA22EFC 78 Bytes [ 57, 8B, 7D, 08, F7, 47, 04, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllCanUnloadNow + 86 7CA22F4B 162 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllCanUnloadNow + 129 7CA22FEE 4 Bytes [ 55, 8B, EC, 56 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!DllCanUnloadNow + 12E 7CA22FF3 13 Bytes [ F1, 8B, 4D, 08, 57, FF, 76, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Unlock + 2 7CA230D4 58 Bytes JMP 7CA22FB1 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Unlock + 3D 7CA2310F 10 Bytes CALL 7CA2404B C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Unlock + 48 7CA2311A 25 Bytes [ 00, 6A, 00, 68, F4, 01, 00, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Unlock + 62 7CA23134 2 Bytes [ 1C, F8 ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotification_Unlock + 66 7CA23138 55 Bytes [ 85, C0, 0F, 84, 8F, FD, FF, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotify + A 7CA235D5 12 Bytes CALL 7C9F05E5 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotify + 17 7CA235E2 28 Bytes CALL 7C9EFEF7 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotify + 34 7CA235FF 10 Bytes CALL 7CA23421 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotify + 3F 7CA2360A 8 Bytes CALL 7CA234F7 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHChangeNotify + 49 7CA23614 4 Bytes CALL 7CA2348F C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractIconExW + 43 7CA24F7E 28 Bytes [ FF, B6, 88, 00, 00, 00, E8, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractIconExW + 60 7CA24F9B 30 Bytes [ 02, 00, 39, 5D, 10, 74, 10, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractIconExW + 7F 7CA24FBA 28 Bytes CALL 7C9E83AC C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractIconExW + 9C 7CA24FD7 15 Bytes [ A1, 48, F5, BC, 7C, 53, 8B, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!ExtractIconExW + AE 7CA24FE9 39 Bytes [ 10, 89, 45, FC, 75, 12, 57, ... ]
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCloneSpecialIDList + 23 7CA252F2 17 Bytes [ D0, 8B, 55, E0, 89, 07, 8D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCloneSpecialIDList + 35 7CA25304 16 Bytes [ 4D, D8, 89, 4F, 0C, 8B, 4D, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCloneSpecialIDList + 46 7CA25315 21 Bytes [ 55, E4, 51, 50, FF, 75, 08, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCloneSpecialIDList + 5C 7CA2532B 41 Bytes [ 75, 08, 8D, 47, 2C, 68, 04, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!SHCloneSpecialIDList + 86 7CA25355 14 Bytes JMP 7CA54E1E C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsExe + 26 7CA25800 99 Bytes CALL 7CA25780 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsExe + 8A 7CA25864 13 Bytes [ FF, 55, 8B, EC, 51, 51, 83, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsExe + 98 7CA25872 27 Bytes [ 4D, F8, 8D, 4D, F8, E8, DB, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsExe + B4 7CA2588E 42 Bytes [ FF, EB, E3, C9, C3, 33, C9, ... ]
.text C:\WINDOWS\System32\svchost.exe[432] SHELL32.dll!PathIsExe + DF 7CA258B9 7 Bytes CALL 7CA25861 C:\WINDOWS\system32\SHELL32.dll (Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows/Microsoft Corporation)
.text ...