This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Reappearence Of Malice

49 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, sorry about the late reply, we've had some flooding here in the uk, crazy weather for this time of year…it affects the internet when water gets in the lines. So, slow internet to go with even slower pc. I still need a bit of help. I am running the GMER thing after this, and post it for you. I have been trying to see what is happening when I stat up, by looking at the processes. I had 51 running on or after start up the other day, with pc at 100% a lot. I know what some are, anti spyware and AV, windows os, yahoo, bt, etc, but I am trying to google some of the processes to see…like svchost.exe, VsMon.exe, AshServ.exe. Probably ok, but they are the ones running high. I know MsMpEng.exe is for windows defender. I need to remove some of the things from start up, how do I do that, so they don't start until I need them?
Ok, the gmer scan has finished….there is a lot to post, so It may take up two or three posts. None of it makes any sense to me…! Actually, i think it will take maybe 10 posts to get this stuff on….what sort of things are you looking for on this log? Can I email it to you instead, or attach it? It's too much to post.
Sorry I don't have an E-mail address for that purpose, you'll just have to break it up into short sections and post here. GMER logs aren't usually that long, did you check "Show All" by chance? (I did instruct not to). If so run another scan with "Show All" unchecked, it should be shorter. Can you send me a new HJT log as well please.
I have just been trying to update my windows form the site, it says there are 75 updates. But none of them will install…Mostly security updates. I have the automatic updating option for my pc, but it looks like it hasn't worked for a while. And I hadn't noticed. One thing after another. If I'm missing security updates, then no wonder I had problems.

Show all was unchecked.

I may take a long time to post it. Are you sure you want it all?


Yes, I can't tell without looking at it what might be the cause of such a long log, it's not usual, and that alone means I need to see it all.

Not sure about the Update problems at the moment, best leave them for the time being until I've had a look at the GMER log, might give some indication as to why.
the updates are working now, waiting for them to load up. 77 of them…lol. I will post the GMER asap…Please bare with me while I get them posted. Thanks for your help, tho.
—- Kernel code sections - GMER 1.0.13 —- .text ntoskrnl.exe!_abnormal_termination + 107 804E2DD8 12 Bytes JMP 6A42AED1 ? srescan.sys The system cannot find the file specified. ? C:\WINDOWS\system32\drivers\sbapifs.sys The system cannot find the file specified. .text ntoskrnl.exe!_abnormal_termination + 107 804E2DD8 12 Bytes JMP 6A42AED1 —- User code sections - GMER 1.0.13 —- .text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[2044] kernel32.dll!WriteFile 7C810F9F 7 Bytes JMP 009FE8D9 C:\Program Files\Windows Desktop Search\mssrch.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NlsMbOemCodePageTag + FFF84FE8 7C901000 19 Bytes [ 89, B5, DC, FD, FF, FF, C7, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnterCriticalSection + F 7C901014 18 Bytes [ 00, 00, 50, 8D, 43, 10, 50, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnterCriticalSection + 23 7C901028 25 Bytes [ C7, 85, E0, FD, FF, FF, 24, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnterCriticalSection + 3D 7C901042 90 Bytes [ 0F, 85, 9D, 00, 00, 00, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnterCriticalSection + 98 7C90109D 59 Bytes CALL 7C900F3F C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnterCriticalSection + D5 7C9010DA 10 Bytes [ 8B, 08, 50, FF, 51, 08, E9, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLeaveCriticalSection + 17 7C901104 45 Bytes [ 00, 00, 8D, 85, DC, FD, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTryEnterCriticalSection + 8 7C901133 5 Bytes [ 8B, 08, 68, 04, 01 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTryEnterCriticalSection + E 7C901139 53 Bytes [ 00, 8D, 95, F4, FD, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTryEnterCriticalSection + 44 7C90116F 50 Bytes [ FF, 8B, 08, 8D, 95, D4, FD, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrInitializeThunk + 24 7C9011A2 20 Bytes [ FF, 74, 1E, FF, B5, E0, FD, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlActivateActivationContextUnsafeFast + 2 7C9011B7 29 Bytes [ B5, E0, FD, FF, FF, 8B, F8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlActivateActivationContextUnsafeFast + 20 7C9011D5 54 Bytes JMP 7C9010DA C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 12 7C90120C 14 Bytes [ 56, FF, 15, 3C, 20, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 21 7C90121B 10 Bytes [ EB, 02, 33, F6, 8B, C6, 5E, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 2C 7C901226 15 Bytes [ 90, 90, 90, 90, 90, 83, 6C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!DbgUserBreakPoint 7C901239 54 Bytes [ 90, 8B, FF, 55, 8B, EC, 81, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitString + 14 7C901270 82 Bytes [ FF, 50, 6A, 01, 6A, 01, 57, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitAnsiString + 2A 7C9012C3 30 Bytes [ FF, 89, 46, 08, FF, 15, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitUnicodeString + C 7C9012E2 171 Bytes [ 74, 1E, 57, 53, 8D, 85, D4, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!cos + 63 7C90138E 122 Bytes [ FF, 89, 9D, B0, FB, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIlog + 36 7C901409 32 Bytes [ 8B, D8, 8D, 85, C8, FB, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIlog + 57 7C90142A 10 Bytes [ 00, 00, EB, D1, 83, A5, C8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIlog + 62 7C901435 16 Bytes [ FF, B5, C8, FB, FF, FF, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIlog + 73 7C901446 30 Bytes [ FF, FF, B5, B8, FB, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIlog + 92 7C901465 10 Bytes [ 89, 46, 08, 74, 0C, FF, B5, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIpow + 32 7C9014E9 57 Bytes [ 4D, FD, FF, FF, 8B, D0, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIpow + 6C 7C901523 38 Bytes CALL 7C9B3C2D .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIpow + 93 7C90154A 38 Bytes [ 85, C0, 74, 04, 33, FF, EB, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIpow + BA 7C901571 3 Bytes [ 46, 1C, 50 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIpow + BE 7C901575 83 Bytes [ 08, B5, EF, FF, 89, BE, 28, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIsin + 7 7C9016D2 3 Bytes [ 29, 25, 0B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIsin + B 7C9016D6 155 Bytes [ 85, C0, 0F, 84, ED, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!sin + 93 7C901772 25 Bytes [ FE, FF, FF, 50, 8D, 85, 80, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_CIsqrt + E 7C90178C 58 Bytes [ 85, C0, 75, 3B, 57, 68, 9C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!sqrt + 35 7C9017C7 92 Bytes [ 80, FE, FF, FF, 83, BD, 80, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!sqrt + 92 7C901824 29 Bytes [ FF, 89, 45, FC, 74, 5A, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldiv + 5 7C901842 94 Bytes [ 35, 64, C5, BB, 7C, FF, D3, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldiv + 64 7C9018A1 40 Bytes [ EC, FF, 75, 0C, 83, C1, 20, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldiv + 8D 7C9018CA 142 Bytes [ 81, C1, 28, 02, 00, 00, 51, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldvrm + 6D 7C901959 5 Bytes [ 08, 50, FF, 51, 08 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldvrm + 73 7C90195F 90 Bytes [ 45, F8, C9, C2, 04, 00, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_alldvrm + CE 7C9019BA 22 Bytes [ 7D, 0C, 57, 8B, F0, E8, 0C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allmul + 1 7C9019D1 29 Bytes [ CE, 8B, 75, 08, 33, C0, F3, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allmul + 1F 7C9019EF 9 Bytes [ EC, 56, 8B, 75, 08, 8B, 46, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allmul + 29 7C9019F9 79 Bytes [ 7D, 0C, 8B, 0F, C1, E9, 1D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allrem 7C901A4B 3 Bytes [ 90, 90, 8B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allrem + 4 7C901A4F 55 Bytes [ 55, 8B, EC, FF, 75, 0C, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allrem + 3C 7C901A87 1 Byte [ FF ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allrem + 3E 7C901A89 30 Bytes CALL 7C7FD659 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allrem + 5D 7C901AA8 79 Bytes [ EC, 56, FF, 75, 14, 68, 54, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_allshr + 1F 7C901B45 154 Bytes [ 1D, 20, 1E, 9C, 7C, 7C, 17, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_aulldvrm + 27 7C901BE0 261 Bytes [ FB, FF, FF, 8B, CF, E8, BA, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_aullshr + 19 7C901CE6 38 Bytes [ 96, 74, 09, 00, 68, 04, 01, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_ftol + 1C 7C901D0D 83 Bytes [ FD, FF, FF, 66, 83, 3B, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_memccpy + 44 7C901D61 79 Bytes [ 23, 00, 56, 57, FF, 75, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!atan + 3C 7C901DB1 36 Bytes [ C1, 28, 51, FF, 75, 0C, 50, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!atan + 61 7C901DD6 288 Bytes CALL 7C7FC8FF .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!ceil + D9 7C901EF7 48 Bytes [ 0E, 8D, 85, F4, FD, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!ceil + 10A 7C901F28 21 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!ceil + 120 7C901F3E 17 Bytes [ 68, 8F, BE, A2, 7C, 50, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!ceil + 132 7C901F50 279 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!floor + 10B 7C902068 4 Bytes [ 00, 68, 09, 30 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!floor + 111 7C90206E 12 Bytes [ 56, FF, 15, D8, 12, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!floor + 11F 7C90207C 20 Bytes [ 56, FF, 15, D4, 12, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!floor + 134 7C902091 123 Bytes [ FF, 15, F4, 12, 9C, 7C, 57, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memchr + 68 7C90210D 40 Bytes [ FF, 8B, 8B, 88, 00, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memchr + 91 7C902136 14 Bytes [ 15, 8C, 19, 9C, 7C, 66, 39, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memchr + A0 7C902145 1 Byte [ 85 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memchr + A2 7C902147 16 Bytes [ F7, FF, FF, 50, 8B, 85, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcmp + 9 7C902158 118 Bytes [ CB, 50, FF, B5, F8, F7, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcmp + 80 7C9021CF 28 Bytes [ FF, 39, BB, 98, 00, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcmp + 9D 7C9021EC 5 Bytes [ FF, E8, AC, F2, FF ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcmp + A3 7C9021F2 44 Bytes [ 01, 85, F4, F7, FF, FF, 01, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcpy + 1F 7C90221F 22 Bytes [ 56, FF, 15, D4, 12, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcpy + 36 7C902236 25 Bytes [ 51, 50, FF, 15, F4, 12, 9C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcpy + 50 7C902250 12 Bytes [ D8, F7, FF, FF, 29, 43, 58, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcpy + 5D 7C90225D 53 Bytes [ 74, 2B, FF, B5, F0, F7, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memcpy + 93 7C902293 63 Bytes [ B5, F4, F7, FF, FF, 57, 6A, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memmove + 24 7C90255E 77 Bytes JMP 7C902454 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memmove + 72 7C9025AC 77 Bytes [ 3D, 8D, 45, 0C, 50, 8B, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memmove + C0 7C9025FA 1 Byte [ 90 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memmove + C2 7C9025FC 104 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memmove + 12B 7C902665 38 Bytes [ 75, E0, 89, 45, DC, 74, 17, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memset + 1 7C90287B 82 Bytes [ 45, 08, 01, 01, 8B, 45, 0C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!memset + 54 7C9028CE 23 Bytes [ 71, 0C, 03, 71, 08, 03, C6, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcpy + F 7C9028E6 6 Bytes [ EC, 56, 8B, 75, 0C, 57 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcat + 1 7C9028ED 7 Bytes [ 7D, 08, 81, C7, E8, 00, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcat + 9 7C9028F5 79 Bytes [ A5, A5, A5, A5, 5F, 33, C0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcat + 59 7C902945 50 Bytes [ 50, 68, E0, 67, 9D, 7C, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcat + 8C 7C902978 8 Bytes [ F0, 85, F6, 7C, 1B, 8B, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcat + 95 7C902981 69 Bytes [ 08, 6A, 01, 8D, 55, FC, 52, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcmp 7C9029D1 67 Bytes [ 90, 8B, 01, 85, C0, 74, 06, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcmp + 44 7C902A15 77 Bytes [ 90, 8B, FF, 56, 8B, F1, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcspn + 8 7C902A63 45 Bytes [ FF, 51, 08, 8B, 86, D8, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strcspn + 36 7C902A91 55 Bytes [ 08, 50, FF, 51, 08, 68, D2, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strlen + 2C 7C902AC9 10 Bytes [ 08, 00, 90, 90, 90, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strlen + 37 7C902AD4 39 Bytes [ EC, 83, 7D, 0C, 00, 74, 4C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strlen + 5F 7C902AFC 31 Bytes [ F8, 85, FF, 7C, 20, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncat + 1 7C902B1C 65 Bytes [ 08, 50, FF, 51, 08, 8B, C7, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncat + 43 7C902B5E 1 Byte [ 83 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncat + 45 7C902B60 16 Bytes [ 00, 00, 00, 83, 38, 00, A5, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncat + 57 7C902B72 27 Bytes CALL 7C812D10 C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncat + 73 7C902B8E 8 Bytes CALL 510C33CE .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncpy + 17 7C902C97 84 Bytes [ 00, 00, FF, 75, 08, 8B, CE, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncpy + 6C 7C902CEC 127 Bytes [ 00, 8B, F8, 8B, 45, 10, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strncpy + EC 7C902D6C 161 Bytes [ 17, 05, 00, 8B, D8, 85, DB, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strspn + 21 7C902E0E 53 Bytes [ 7E, 14, 6A, 00, 6A, 00, 57, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!tan + 6 7C902E44 2 Bytes [ C8, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!tan + 9 7C902E47 46 Bytes CALL 7C85CB2B C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!tan + 39 7C902E77 47 Bytes [ 85, C0, 89, 55, 0C, 74, 0E, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!tan + 69 7C902EA7 34 Bytes [ 6A, 00, FF, 76, 14, 50, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!tan + 8C 7C902ECA 42 Bytes [ 5F, 5E, C9, C2, 10, 00, 90, … ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUlongByteSwap + B 7C902FD4 39 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCompareMemory + 6 7C902FFC 65 Bytes [ 8B, 08, FF, 75, 20, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCompareMemory + 48 7C90303E 49 Bytes [ 4B, FC, FF, 75, 18, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCompareMemoryUlong + 27 7C903072 116 Bytes [ 56, 57, 33, C0, 33, FF, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFillMemory + 67 7C9030E7 16 Bytes [ 85, C0, 74, 14, 8B, 08, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFillMemoryUlong + 3 7C9030F8 19 Bytes [ 06, 39, 5D, 08, 74, 01, 43, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFillMemoryUlong + 17 7C90310C 27 Bytes [ 90, 8B, FF, 55, 8B, EC, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlZeroMemory + D 7C903128 34 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlZeroMemory + 30 7C90314B 170 Bytes [ 74, 14, 46, 83, C0, 04, 83, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMoveMemory + A5 7C9031F6 86 Bytes [ 84, D5, 00, 00, 00, 39, B3, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMoveMemory + FC 7C90324D 39 Bytes [ 43, 14, 33, C9, 48, 83, F8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMoveMemory + 124 7C903275 96 Bytes CALL 7C902C2B C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMoveMemory + 185 7C9032D6 10 Bytes [ 74, 0E, 83, FA, 02, 74, 09, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMoveMemory + 190 7C9032E1 63 Bytes [ 85, 91, 00, 00, 00, 6A, 06, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnlargedUnsignedDivide + 14 7C903514 8 Bytes [ 07, 80, EB, 0D, C7, 45, B8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEnlargedUnsignedDivide + 1D 7C90351D 11 Bytes [ 04, 80, EB, 04, 83, 65, B8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedLargeIntegerDivide + 4 7C903529 98 Bytes CALL 7C7FD91E .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedMagicDivide + 5 7C90358C 54 Bytes [ A5, 89, 45, FC, 8B, 45, 0C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedMagicDivide + 3C 7C9035C3 23 Bytes [ FF, 75, E0, 8D, 75, EC, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedMagicDivide + 54 7C9035DB 65 Bytes [ 04, 00, 74, 0D, FF, 45, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedIntegerMultiply 7C90361D 4 Bytes [ 90, 90, 90, 90 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExtendedIntegerMultiply + 5 7C903622 96 Bytes [ FF, 53, 56, 57, 8B, D9, 68, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLargeIntegerShiftLeft + 8 7C903683 148 Bytes [ F8, 00, 00, 00, 83, 60, 04, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLargeIntegerNegate + 12 7C903718 15 Bytes [ 75, 10, 6A, 04, 8D, 8E, F8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLargeIntegerSubtract + 9 7C903728 75 Bytes [ 55, 18, 39, 9D, F0, FD, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertUlongToLargeInteger + 2F 7C903774 10 Bytes [ 38, 68, 04, 01, 00, 00, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertUlongToLargeInteger + 3A 7C90377F 67 Bytes [ FF, 50, 8B, 85, F0, FD, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertUlongToLargeInteger + 7E 7C9037C3 54 Bytes [ 74, 10, 8B, 08, 6A, 20, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertUlongToLargeInteger + B6 7C9037FB 22 Bytes [ 3B, C3, 74, 22, 39, 9D, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertUlongToLargeInteger + CE 7C903813 38 Bytes [ 8B, 08, 53, 68, B4, 43, 9C, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCaptureContext + C 7C903851 36 Bytes CALL 08903853 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCaptureContext + 31 7C903876 36 Bytes [ 8B, 86, D0, 00, 00, 00, 3B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCaptureContext + 58 7C90389D 5 Bytes [ 74, 36, 8B, 86, D0 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCaptureContext + 60 7C9038A5 7 Bytes [ 3B, C3, 74, 0C, 89, 9E, D0 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCaptureContext + 6A 7C9038AF 9 Bytes [ 8B, 08, 50, FF, 51, 08, 81, … ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAcceptConnectPort + D 7C90D386 1 Byte [ 0C ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAcceptConnectPort + 14 7C90D38D 7 Bytes [ 8B, FF, 56, 8D, B1, D8, 1C ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAccessCheck + 7 7C90D395 87 Bytes [ 00, 83, 3E, 00, 75, 1F, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAccessCheckByTypeResultList + B 7C90D3ED 33 Bytes [ FF, 50, 8D, 85, 7C, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarmByHandle + 3 7C90D40F 85 Bytes [ FF, 15, A8, 1A, 9C, 7C, 85, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAdjustPrivilegesToken + 5 7C90D465 39 Bytes [ 00, 57, 8B, BE, 78, 1C, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAlertThread + 3 7C90D48D 24 Bytes [ FF, 8B, CE, 89, 86, 84, 1C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAllocateLocallyUniqueId + 7 7C90D4A6 47 Bytes [ 6A, 00, 68, 04, 06, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAllocateUuids + D 7C90D4D6 1 Byte [ 04 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAllocateUuids + 14 7C90D4DD 53 Bytes [ 8B, FF, 55, 8B, EC, 53, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtAssignProcessToJobObject + B 7C90D513 16 Bytes CALL 7C90CF49 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCallbackReturn + 7 7C90D524 62 Bytes [ 00, 8B, 07, 85, C0, 74, 16, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCancelTimer + 7 7C90D563 28 Bytes [ 00, 00, 3B, C1, 74, 1C, 51, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtClearEvent + F 7C90D580 12 Bytes [ 00, 01, 00, 00, 00, 5E, 33, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtClose + 7 7C90D58D 108 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCompressKey + B 7C90D5FA 44 Bytes [ 52, 0C, 8B, F0, 85, F6, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtContinue + E 7C90D627 19 Bytes [ 8B, 08, 50, FF, 51, 08, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateDebugObject + D 7C90D63B 1 Byte [ 0C ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateDebugObject + 14 7C90D642 45 Bytes [ 8B, FF, 55, 8B, EC, 51, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateEventPair + 3 7C90D670 104 Bytes [ 85, C9, 75, 03, 8B, 48, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateKey + 3 7C90D6D9 20 Bytes [ 85, C0, 75, 11, 8B, 47, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateMailslotFile + 3 7C90D6EE 74 Bytes [ 8B, CF, BE, 05, 40, 00, 80, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreatePagingFile + F 7C90D739 30 Bytes [ 83, 7D, 08, 00, 74, 4F, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateProcess + 5 7C90D759 39 Bytes [ 00, 8B, 45, 08, 83, EC, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateProfile + 3 7C90D781 70 Bytes [ 8B, F0, 8B, 45, 08, 8B, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateSymbolicLinkObject + B 7C90D7C8 13 Bytes CALL CD367D72 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtCreateThread + 5 7C90D7D7 106 Bytes [ 00, 8B, F0, 8D, 45, D8, 50, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDebugContinue + 7 7C90D842 24 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDelayExecution + B 7C90D85B 8 Bytes CALL 7C90D112 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDelayExecution + 14 7C90D864 91 Bytes [ 1B, 00, 00, 85, F6, 74, 4E, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDeleteObjectAuditAlarm + 7 7C90D8C0 50 Bytes [ 90, 90, 90, 90, 90, 33, C0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDeviceIoControlFile + 13 7C90D8F6 38 Bytes [ 8B, FF, 55, 8B, EC, 8B, 4D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtDuplicateObject + 11 7C90D91E 82 Bytes [ 8B, FF, 55, 8B, EC, F6, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtEnumerateSystemEnvironmentValuesEx + 11 7C90D972 65 Bytes [ 8B, FF, 55, 8B, EC, 8B, D1, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtFindAtom 7C90D9B5 73 Bytes [ 90, 90, 90, 8B, FF, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtFlushKey + B 7C90D9FF 11 Bytes [ 51, 08, 8B, 46, 08, 85, C0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtFlushVirtualMemory + 2 7C90DA0B 18 Bytes [ FF, 51, 08, 8B, 76, 04, 85, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtFlushWriteBuffer 7C90DA1E 46 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtFreeVirtualMemory + 5 7C90DA4D 60 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtGetDevicePowerState + 3 7C90DA8A 314 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtLockProductActivationKeys + 4 7C90DBC6 166 Bytes [ 8B, 46, 04, 8B, 08, 8D, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtModifyBootEntry + 5 7C90DC6F 9 Bytes [ 8B, 46, 44, A8, 08, 0F, 85, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtModifyBootEntry + F 7C90DC79 56 Bytes [ 00, 83, C8, 08, 89, 46, 44, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtNotifyChangeMultipleKeys + 9 7C90DCB2 1 Byte [ FF ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtNotifyChangeMultipleKeys + B 7C90DCB4 238 Bytes [ 8B, 08, 50, FF, 51, 08, E9, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtOpenProcessTokenEx 7C90DDA5 65 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtOpenSymbolicLinkObject + 3 7C90DDE7 75 Bytes [ 75, 09, F6, 45, 17, 40, 74, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtOpenThreadTokenEx + 11 7C90DE34 48 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtPowerInformation + 4 7C90DE66 90 Bytes [ FF, 70, 34, FF, 15, 50, 13, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtProtectVirtualMemory + B 7C90DEC1 7 Bytes [ FF, 33, C0, 5D, C2, 10, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtPulseEvent 7C90DECB 15 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtPulseEvent + 12 7C90DEDD 177 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryEaFile + 7 7C90DF8F 24 Bytes [ 00, 00, FF, 77, 4C, FF, 15, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryEvent + B 7C90DFA8 66 Bytes [ 54, 3F, AF, 7C, 5C, 3F, AF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryInformationFile + F 7C90DFEB 100 Bytes CALL 7C90DF13 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryInformationToken + B 7C90E050 33 Bytes CALL 7C807D7C C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryIntervalProfile + 3 7C90E072 3 Bytes [ BB, 05, 40 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryIntervalProfile + 7 7C90E076 17 Bytes [ 80, FF, B5, F0, FD, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryIoCompletion + 4 7C90E088 16 Bytes [ 80, 5F, 8B, 4D, FC, 5E, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryKey 7C90E099 27 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryMultipleValueKey + 7 7C90E0B5 16 Bytes [ 00, 00, 56, 8D, 77, 34, 39, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryMutant + 3 7C90E0C6 42 Bytes [ 39, 4D, 08, 74, 11, 8B, 5F, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryOpenSubKeys + 4 7C90E0F1 27 Bytes [ 80, 85, DB, 7C, 47, 8D, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryPerformanceCounter + B 7C90E10D 41 Bytes CALL 7C800900 C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQuerySection + B 7C90E137 30 Bytes [ 51, 08, 85, DB, 7D, 0F, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQuerySemaphore 7C90E156 36 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQuerySymbolicLinkObject + 10 7C90E17B 66 Bytes [ 8B, FF, 55, 8B, EC, 53, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQuerySystemTime 7C90E1BF 46 Bytes [ 90, 90, 90, 8B, FF, 55, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtQueryTimerResolution + 5 7C90E1EE 125 Bytes [ 74, 1C, FF, 75, 0C, 83, C0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRaiseHardError + 5 7C90E26C 7 Bytes [ 00, FF, 5F, 8B, C2, 5E, 5D ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRaiseHardError + D 7C90E274 1 Byte [ 08 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRaiseHardError + 14 7C90E27B 24 Bytes [ 8B, FF, 56, 8B, F1, E8, 46, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtReadFileScatter + 3 7C90E294 14 Bytes [ 68, 58, 36, 9C, 7C, 6A, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtReadRequestData 7C90E2A6 37 Bytes [ 90, 8B, FF, 55, 8B, EC, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRegisterThreadTerminatePort 7C90E2D0 7 Bytes [ 8D, 41, 48, 83, 38, 00, 74 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRegisterThreadTerminatePort + 8 7C90E2D8 72 Bytes [ 33, C0, C3, 50, 68, A0, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRemoveProcessDebug 7C90E324 99 Bytes [ 90, 8B, FF, 55, 8B, EC, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtReplyWaitReceivePort + 10 7C90E388 15 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtReplyWaitReceivePortEx + B 7C90E398 109 Bytes [ FF, 85, C0, 7C, 15, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtRequestWakeupLatency + 11 7C90E407 108 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSaveKey 7C90E474 31 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSaveKeyEx + B 7C90E494 12 Bytes [ 75, 0C, 8B, 08, 50, FF, 51, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSaveMergedKeys + 3 7C90E4A1 42 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetBootEntryOrder + 4 7C90E4CC 6 Bytes [ 90, 90, 90, 90, 90, 8B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetBootEntryOrder + B 7C90E4D3 130 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetDefaultUILanguage + 12 7C90E558 39 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetEvent + 13 7C90E583 35 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetHighEventPair + D 7C90E5A7 1 Byte [ 08 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetHighEventPair + 14 7C90E5AE 38 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationFile 7C90E5D9 38 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationKey 7C90E603 31 Bytes [ 90, 8B, FF, 55, 8B, EC, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationObject + B 7C90E623 7 Bytes [ 51, 3C, 5E, 5D, C2, 08, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationProcess 7C90E62D 45 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationToken + 4 7C90E65B 6 Bytes [ 90, 90, 90, 90, 90, 8B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetInformationToken + B 7C90E662 89 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetLowWaitHighEventPair 7C90E6C0 41 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetSecurityObject 7C90E6EA 31 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetSystemEnvironmentValue + B 7C90E70A 67 Bytes [ 75, 14, 8B, 08, FF, 75, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetSystemPowerState + 12 7C90E750 41 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetTimer 7C90E77D 90 Bytes [ 90, 8B, FF, 55, 8B, EC, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSetVolumeInformationFile + 7 7C90E7D8 45 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSignalAndWaitForSingleObject + B 7C90E806 20 Bytes [ 75, 0C, 8B, 08, 50, FF, 51, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtStartProfile + B 7C90E81B 8 Bytes [ 8B, C7, 5F, 5E, 5D, C2, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtStopProfile 7C90E825 41 Bytes [ 90, 90, 90, 8B, FF, 55, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtSuspendThread 7C90E84F 55 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtTerminateJobObject + E 7C90E887 74 Bytes CALL 7C90E2CD C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtTraceEvent + 5 7C90E8D2 26 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtTranslateFilePath + B 7C90E8ED 62 Bytes [ 75, 10, 8B, 46, 40, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtUnloadKeyEx + B 7C90E92C 34 Bytes [ 75, 18, 8B, 08, FF, 75, 14, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtUnlockVirtualMemory + 4 7C90E94F 6 Bytes [ 90, 90, 90, 90, 90, 8B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtUnlockVirtualMemory + B 7C90E956 41 Bytes [ 55, 8B, EC, 8B, 4D, 08, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtVdmControl + B 7C90E980 20 Bytes [ 75, 14, FF, 75, 10, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtWaitForDebugEvent + B 7C90E995 9 Bytes [ 51, 08, 8B, C6, 5E, 5D, C2, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtWaitForMultipleObjects 7C90E99F 52 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtWaitHighEventPair + B 7C90E9D4 88 Bytes [ 51, 0C, 8B, F0, 8B, 45, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!NtWriteRequestData + 13 7C90EA30 170 Bytes [ 8B, FF, 56, 8B, F1, 8D, 46, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!KiUserCallbackDispatcher + B 7C90EADB 5 Bytes [ CE, E8, 9A, F6, FF ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!KiUserCallbackDispatcher + 11 7C90EAE1 50 Bytes [ 8B, D8, 85, DB, 0F, 8C, D7, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!KiUserExceptionDispatcher + 29 7C90EB15 77 Bytes [ 8B, 11, 8D, 7E, 3C, 57, 68, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!KiRaiseUserExceptionDispatcher + 27 7C90EB64 68 Bytes [ 8D, BD, E4, FB, FF, FF, F3, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!KiIntSystemCall + 4 7C90EBA9 14 Bytes [ 8B, 85, D8, FB, FF, FF, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlRaiseException + D 7C90EBB9 1 Byte [ FB ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlRaiseException + 10 7C90EBBC 6 Bytes [ 8B, 08, 50, FF, 51, 08 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlRaiseException + 17 7C90EBC3 68 Bytes [ 4D, FC, 5E, 8B, C3, 5B, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlRaiseException + 5C 7C90EC08 67 Bytes CALL 7C90EA30 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlRaiseException + A0 7C90EC4C 15 Bytes CALL 7C90EBD5 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strstr + 53 7C90ECC2 31 Bytes [ 0C, 50, FF, 51, 0C, 8B, F8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strstr + 73 7C90ECE2 4 Bytes [ 55, 8B, EC, 56 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strstr + 78 7C90ECE7 72 Bytes [ 75, 08, 57, 6A, 01, 8B, CE, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strchr + 2F 7C90ED30 10 Bytes [ 75, 08, 57, 6A, 01, 8B, CE, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strchr + 3A 7C90ED3B 106 Bytes [ FF, 8B, F8, 85, FF, 7C, 40, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strchr + A5 7C90EDA6 23 Bytes [ 75, 14, 8B, 46, 3C, FF, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strchr + C0 7C90EDC1 47 Bytes [ 8B, FF, 55, 8B, EC, 53, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!strchr + F1 7C90EDF2 205 Bytes [ 08, 7C, 2C, 57, 6A, 04, 59, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAnsiStringToUnicodeString + 13 7C90F05F 92 Bytes [ FF, 75, 10, 8B, 46, 40, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAnsiStringToUnicodeString + 70 7C90F0BC 43 Bytes [ 9B, 25, EF, FF, 8B, F0, 53, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAnsiStringToUnicodeString + 9C 7C90F0E8 86 Bytes [ 83, 38, 00, 75, 2D, 50, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAnsiStringToUnicodeString + F3 7C90F13F 3 Bytes [ 57, 8D, 7E ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAnsiStringToUnicodeString + F7 7C90F143 41 Bytes CALL 7C90EA4C C:\WINDOWS\system32\ntdll.dll .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMultiByteToUnicodeN 7C90F1CB 6 Bytes [ 90, 8B, FF, 55, 8B, EC ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMultiByteToUnicodeN + 7 7C90F1D2 29 Bytes [ 8B, 75, 08, 57, 8D, 4E, E0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMultiByteToUnicodeN + 25 7C90F1F0 79 Bytes CALL 7C808FF0 C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMultiByteToUnicodeN + 75 7C90F240 523 Bytes CALL 7C90EA4C C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlMultiByteToUnicodeN + 281 7C90F44C 59 Bytes [ 90, 90, 90, 90, 90, 83, 6C, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosError + 6 7C90FB43 101 Bytes [ 90, 90, 90, 90, 83, 6C, 24, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosErrorNoTeb + 21 7C90FBAA 7 Bytes [ 00, C7, 40, 54, 10, 00, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosErrorNoTeb + 29 7C90FBB2 133 Bytes [ C3, 90, 90, 90, 90, 90, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosErrorNoTeb + B0 7C90FC39 1 Byte [ 08 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosErrorNoTeb + B7 7C90FC40 77 Bytes [ 8B, FF, 55, 8B, EC, 8B, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlNtStatusToDosErrorNoTeb + 105 7C90FC8E 23 Bytes [ 85, C0, 89, 06, 74, 0D, FF, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAddRefActivationContext + 4D 7C91012F 56 Bytes JMP C3587DD0 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAddRefActivationContext + 87 7C910169 12 Bytes [ 8B, 06, 56, FF, 50, 08, 5E, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAddRefActivationContext + 94 7C910176 7 Bytes [ 8B, FF, 55, 8B, EC, 56, 57 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAddRefActivationContext + 9C 7C91017E 65 Bytes [ 7D, 0C, BE, 24, 38, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAddRefActivationContext + DE 7C9101C0 6 Bytes [ 0C, 68, D4, E1, AE, 7C ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryInformationActivationContext + 12 7C9101F4 88 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryInformationActivationContext + 6B 7C91024D 7 Bytes [ 80, C7, 45, EC, 40, 01, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryInformationActivationContext + 73 7C910255 138 Bytes [ C7, 45, F8, C8, B8, 9D, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryInformationActivationContext + FE 7C9102E0 18 Bytes [ 89, B5, EC, FD, FF, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryInformationActivationContext + 112 7C9102F4 29 Bytes [ 50, FF, 15, 3C, 20, 9C, 7C, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLastWin32Error + 4 7C910335 119 Bytes [ 51, 8D, 85, EC, FD, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitUnicodeStringEx + 8 7C9103AD 291 Bytes [ 1B, 57, 53, 8D, 85, F4, FD, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFreeHeap + 94 7C9104D1 49 Bytes [ B5, EC, FD, FF, FF, FF, 15, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFreeHeap + C7 7C910504 120 Bytes [ A1, 08, C5, BB, 7C, 53, 56, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFreeHeap + 140 7C91057D 17 Bytes [ C7, 85, DC, F1, FF, FF, 04, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFreeHeap + 152 7C91058F 13 Bytes [ FF, FF, 15, C0, 1C, 9C, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFreeHeap + 160 7C91059D 6 Bytes [ 00, 8D, 85, D8, F1, FF ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAllocateHeap + F 7C9105E3 67 Bytes [ FF, 08, 00, 00, 00, FF, 15, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAllocateHeap + 53 7C910627 10 Bytes [ 50, 8D, 85, E4, F9, FF, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAllocateHeap + 5E 7C910632 191 Bytes [ 36, 9D, 7C, 56, FF, B5, D8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAllocateHeap + 11F 7C9106F3 42 Bytes [ 50, 8D, 84, 7D, E4, F1, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAllocateHeap + 14A 7C91071E 26 Bytes [ B5, D8, F1, FF, FF, FF, 15, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageDirectoryEntryToData + 1A 7C910870 31 Bytes [ 74, 09, 83, 38, 0A, 7E, 04, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageDirectoryEntryToData + 3A 7C910890 163 Bytes [ 56, 57, 6A, 02, 5A, 33, DB, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAcquirePebLock + 18 7C910935 347 Bytes CALL 7C837197 C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsncpy + 2 7C910A91 21 Bytes [ 75, 08, 8B, 4D, 0C, E8, 13, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsncpy + 18 7C910AA7 37 Bytes [ EC, 81, EC, 90, 05, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsncpy + 3E 7C910ACD 129 Bytes [ 01, 00, 00, 8D, BD, A8, FA, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsncpy + C0 7C910B4F 24 Bytes [ 8B, 3D, 20, BA, 9E, 7C, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsncpy + D9 7C910B68 36 Bytes [ FF, 00, 89, 85, 9C, FA, FF, … ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeleteCriticalSection + C 7C911896 32 Bytes [ FF, 8B, 07, 81, C1, 08, 02, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeleteCriticalSection + 2D 7C9118B7 37 Bytes [ 07, 57, FF, 50, 08, 8B, 93, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeleteCriticalSection + 54 7C9118DE 47 Bytes [ 8B, BD, A4, FD, FF, FF, 8D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeleteCriticalSection + 85 7C91190F 20 Bytes [ 04, 74, 0A, 57, 8B, CB, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDeleteCriticalSection + 9A 7C911924 87 Bytes [ 8D, 78, 04, F3, A5, 83, 88, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSectionAndSpinCount + 20 7C911A4A 42 Bytes [ 6A, 40, FF, 15, 84, 1A, 9C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSectionAndSpinCount + 4B 7C911A75 178 Bytes [ B3, D0, 00, 00, 00, FF, 15, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLogStackBackTrace + 44 7C911B28 144 Bytes [ 56, 8B, F1, 8B, 8E, E0, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSection + 8C 7C911BB9 23 Bytes CALL 7C911681 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSection + A4 7C911BD1 18 Bytes CALL 7C91180A C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSection + B7 7C911BE4 25 Bytes CALL 7C8E16C8 C:\WINDOWS\system32\kernel32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSection + D1 7C911BFE 52 Bytes [ 15, F4, 17, 9C, 7C, 6A, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlInitializeCriticalSection + 106 7C911C33 1 Byte [ 4D ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTimeToTimeFields + 5E 7C91246B 11 Bytes [ 74, 0D, 6A, 00, 6A, FC, E8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTimeToTimeFields + 6A 7C912477 156 Bytes [ C0, 7C, 6E, 8B, 76, 04, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTimeToTimeFields + 109 7C912516 8 Bytes [ 8D, 85, FC, FE, FF, FF, 50, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTimeToTimeFields + 112 7C91251F 184 Bytes [ 73, 00, 00, FF, 35, 64, C5, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlTimeToTimeFields + 1CB 7C9125D8 157 Bytes JMP 7C9126EB C:\WINDOWS\system32\ntdll.dll .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrFindResource_U 7C912C81 5 Bytes [ 90, 90, 90, 90, 8B ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrFindResource_U + 6 7C912C87 16 Bytes [ 55, 8B, EC, 8B, 45, 08, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrFindResource_U + 18 7C912C99 9 Bytes [ 75, 14, F7, D8, FF, 75, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrAccessResource + 1 7C912CA3 20 Bytes [ 75, 0C, 23, C1, FF, 70, 4C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrAccessResource + 16 7C912CB8 1 Byte [ 14 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrAccessResource + 18 7C912CBA 59 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLoadAlternateResourceModule + 21 7C912CF6 12 Bytes [ 4A, 28, 89, 48, 04, 33, C0, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLoadAlternateResourceModule + 2E 7C912D03 230 Bytes [ 90, 90, 90, 8B, FF, 55, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageRvaToSection + 6 7C912DEA 85 Bytes [ 08, 57, FF, 75, 0C, 50, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageRvaToSection + 5C 7C912E40 25 Bytes [ 50, FF, 51, 08, 8B, C6, 5E, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageRvaToSection + 76 7C912E5A 25 Bytes [ C6, 04, 83, 3E, 00, 75, 21, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageRvaToSection + 90 7C912E74 24 Bytes CALL 7C99D9D0 C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlImageRvaToSection + A9 7C912E8D 38 Bytes [ 4D, 0C, 89, 01, 33, C0, EB, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteN + 1A 7C912FB5 78 Bytes [ 57, 57, 57, FF, 73, 14, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteN + 69 7C913004 65 Bytes [ 5E, 75, 0B, 6A, FF, FF, 73, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteN + AC 7C913047 194 Bytes [ 70, 08, 57, 03, F0, 56, 03, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeStringToAnsiString + 45 7C91310B 69 Bytes [ 38, 89, 46, 34, 89, 46, 30, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeStringToAnsiString + 8B 7C913151 95 Bytes [ 89, 45, FC, FF, 15, 44, 13, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLockLoaderLock + 40 7C9131B1 23 Bytes [ 45, 08, FF, 75, 0C, 8B, C8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLockLoaderLock + 58 7C9131C9 7 Bytes CALL 7C912CBE C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLockLoaderLock + 60 7C9131D1 37 Bytes [ 08, 00, 90, 90, 90, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLockLoaderLock + 86 7C9131F7 7 Bytes [ 75, 18, 23, C8, FF, 75, 14 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrLockLoaderLock + 8E 7C9131FF 71 Bytes [ 75, 10, FF, 75, 0C, E8, 09, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrUnlockLoaderLock + 1E 7C913247 7 Bytes CALL 3498A65C .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!LdrUnlockLoaderLock + 26 7C91324F 82 Bytes [ 04, 80, EB, 65, 39, 55, 14, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!CsrClientCallServer + 1 7C9132A2 2 Bytes [ 06, 51 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!CsrClientCallServer + 4 7C9132A5 2 Bytes [ CE, C7 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!CsrClientCallServer + 7 7C9132A8 26 Bytes [ C4, 3C, 00, 00, 00, 89, 5D, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!CsrClientCallServer + 22 7C9132C3 70 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!CsrClientCallServer + 69 7C91330A 7 Bytes [ 50, 14, 89, 11, 83, 78, 14 ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_strcmpi + 15 7C913389 509 Bytes [ 46, 44, F6, C4, 10, 74, 0B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlValidSid + F0 7C913587 6 Bytes [ 00, 00, 5D, C2, 08, 00 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCreateUnicodeStringFromAsciiz 7C913591 64 Bytes [ 90, 8B, FF, 55, 8B, EC, 83, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsDosDeviceName_U + 12 7C9135D2 53 Bytes [ 85, C0, 75, 03, FF, 45, 0C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsDosDeviceName_U + 48 7C913608 15 Bytes [ 4D, 0C, 74, 6C, 8B, C3, 89, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsDosDeviceName_U + 58 7C913618 16 Bytes [ 75, 51, 8B, 36, 68, 38, 36, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsDosDeviceName_U + 6A 7C91362A 2 Bytes [ 85, C0 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsDosDeviceName_U + 6D 7C91362D 28 Bytes [ 3D, 21, 45, F8, 39, 45, FC, … ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCopySid + 12 7C913694 29 Bytes [ 75, 07, B8, 03, 40, 00, 80, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCopySid + 32 7C9136B4 69 Bytes [ 8B, FF, 55, 8B, EC, 57, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteSize + 2B 7C9136FD 6 Bytes [ 90, 8B, FF, 55, 8B, EC ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteSize + 32 7C913704 1 Byte [ 4D ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnicodeToMultiByteSize + 34 7C913706 30 Bytes [ 8D, 81, 54, FF, FF, FF, F7, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlLockHeap + 2 7C913725 182 Bytes [ 50, 10, 5D, C2, 08, 00, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnlockHeap + 51 7C9137DC 5 Bytes [ 90, 90, 90, 90, 83 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlUnlockHeap + 57 7C9137E2 67 Bytes [ 24, 04, 10, EB, 92, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsValidHandle + 33 7C913828 42 Bytes [ 83, 6C, 24, 04, 18, E9, 30, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlIsValidHandle + 60 7C913855 55 Bytes [ 83, 6C, 24, 04, 20, E9, 1A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_wcsicmp 7C913890 76 Bytes [ 90, 83, 6C, 24, 04, 28, E9, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!_wcsicmp + 4D 7C9138DD 54 Bytes JMP 7C91375E C:\WINDOWS\system32\ntdll.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlEncodePointer 7C913917 39 Bytes [ 90, 83, 6C, 24, 04, 38, E9, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDecodePointer + 2 7C91393F 96 Bytes [ FF, 90, 90, 90, 90, 90, 83, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDetermineDosPathNameType_U + 1 7C9139A0 100 Bytes CALL D3A58730 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDetermineDosPathNameType_U + 66 7C913A05 12 Bytes [ 76, 04, FF, D7, FF, 75, 14, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDetermineDosPathNameType_U + 73 7C913A12 92 Bytes [ 00, 00, 89, 45, 0C, E8, A8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDetermineDosPathNameType_U + D1 7C913A70 3 Bytes [ 00, 8B, F0 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDetermineDosPathNameType_U + D5 7C913A74 174 Bytes [ F6, 74, 0A, 8B, 06, 56, FF, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDosPathNameToNtPathName_U + 5B 7C914158 47 Bytes [ FF, 50, 68, 01, 00, 00, 80, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlDosPathNameToNtPathName_U + 8B 7C914188 130 Bytes [ FF, 55, 8B, EC, 83, EC, 10, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetFullPathName_U + 5A 7C91420B 371 Bytes [ 51, 08, 8B, C7, 5F, C9, C2, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetCurrentDirectory_U + 70 7C91437F 49 Bytes [ 55, 8B, EC, 6A, 00, 6A, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryEnvironmentVariable_U + 10 7C9143B1 161 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryEnvironmentVariable_U + B2 7C914453 37 Bytes [ 89, 06, 8B, 06, 5E, EB, D3, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlQueryEnvironmentVariable_U + D8 7C914479 32 Bytes [ D7, 83, 26, 00, 8B, 46, 04, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsrchr + 1 7C91449A 14 Bytes [ 46, 30, 85, C0, 74, 0B, 50, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!wcsrchr + 10 7C9144A9 60 Bytes [ 30, 00, 5F, 5E, C3, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExpandEnvironmentStrings_U + 14 7C9144E6 2 Bytes [ FF, 55 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExpandEnvironmentStrings_U + 17 7C9144E9 35 Bytes [ EC, 83, EC, 3C, 56, 57, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExpandEnvironmentStrings_U + 3B 7C91450D 141 Bytes CALL 7C9D6990 C:\WINDOWS\system32\SHELL32.dll .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExpandEnvironmentStrings_U + CA 7C91459C 92 Bytes [ 8B, F0, 8B, 4D, FC, 8B, C6, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlExpandEnvironmentStrings_U + 127 7C9145F9 50 Bytes [ 9C, 7C, 8D, 45, F4, 50, E8, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLongestNtPathLength + 21 7C914800 20 Bytes [ F0, 81, FE, 20, 04, 00, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLongestNtPathLength + 36 7C914815 131 Bytes [ 1B, 9C, 7C, 85, C0, 74, 0C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLongestNtPathLength + BA 7C914899 11 Bytes [ 40, 5D, C2, 04, 00, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLongestNtPathLength + C6 7C9148A5 94 Bytes [ 55, 8B, EC, 66, 83, 7D, 08, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlGetLongestNtPathLength + 125 7C914904 98 Bytes [ 74, 04, 8B, C6, 5E, C3, 33, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertSidToUnicodeString + 22 7C914A7F 2 Bytes [ 90, FE ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertSidToUnicodeString + 26 7C914A83 121 Bytes [ 3B, C6, 75, 6C, 56, 68, 64, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertSidToUnicodeString + A0 7C914AFD 60 Bytes [ 5B, 5D, C2, 08, 00, 90, 90, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertSidToUnicodeString + DE 7C914B3B 3 Bytes [ 66, 39, 18 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlConvertSidToUnicodeString + E2 7C914B3F 7 Bytes [ 84, 95, 00, 00, 00, 66, 8B ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCopyUnicodeString + 13 7C914CF4 11 Bytes [ 8D, 4D, C8, 51, 50, 6A, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlCopyUnicodeString + 1F 7C914D00 113 Bytes [ 00, 00, FF, D6, 85, C0, 75, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAppendUnicodeToString + 30 7C914D72 30 Bytes [ 73, 42, 68, 8C, 0C, 9D, 7C, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlAppendUnicodeToString + 4F 7C914D91 199 Bytes [ F3, FF, 73, 14, 8D, 7D, 98, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFormatCurrentUserKeyPath + 38 7C914E59 17 Bytes [ 75, 21, 8B, 43, 04, F7, D8, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFormatCurrentUserKeyPath + 4A 7C914E6B 28 Bytes [ 15, 30, 14, 9C, 7C, 8D, 45, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFormatCurrentUserKeyPath + 67 7C914E88 101 Bytes [ 15, 30, 16, 9C, 7C, 8B, 0B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFormatCurrentUserKeyPath + CD 7C914EEE 47 Bytes [ 08, 56, 8B, F1, 83, 26, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFormatCurrentUserKeyPath + FD 7C914F1E 1 Byte [ 00 ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!bsearch + 27 7C915022 96 Bytes CALL 7C7FCA80 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!bsearch + 88 7C915083 33 Bytes [ 39, 46, 78, 75, 06, 8B, 86, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!bsearch + AA 7C9150A5 21 Bytes [ E0, FD, 53, 89, 55, E8, 89, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!bsearch + C0 7C9150BB 6 Bytes [ 8B, 1F, 0F, 84, 54, 02 ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!bsearch + C8 7C9150C3 27 Bytes [ 8B, 08, 8D, 55, FC, 52, 50, … ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFindActivationContextSectionString + 1F 7C915338 32 Bytes [ FF, 75, 0C, 8B, 08, 50, FF, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFindActivationContextSectionString + 40 7C915359 30 Bytes [ 51, 50, FF, 52, 20, 8B, 86, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFindActivationContextSectionString + 5F 7C915378 37 Bytes [ FF, 51, 34, 6A, 00, 6A, 04, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFindActivationContextSectionString + 85 7C91539E 42 Bytes [ C4, 10, 5E, 5D, C2, 08, 00, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlFindActivationContextSectionString + B0 7C9153C9 6 Bytes [ FF, FF, 75, 08, 8B, CE ] .text … .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlHashUnicodeString + 18 7C91547D 21 Bytes [ 00, 8B, 08, 8D, 55, F8, 52, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlHashUnicodeString + 2E 7C915493 64 Bytes [ 60, 04, FE, FF, 45, 08, 8B, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlHashUnicodeString + 6F 7C9154D4 48 Bytes [ 00, 85, C0, 74, 0D, FF, 77, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlHashUnicodeString + A0 7C915505 18 Bytes [ 00, 00, 8B, 10, 6A, 01, 6A, … ] .text C:\WINDOWS\system32\wbem\wmiprvse.exe[3400] ntdll.dll!RtlHashUnicodeString + B4 7C915519 50 Bytes [ 8B, 08, 8D, 55, F4, 52, 50, … ]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI