This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] svchost errors - driving me crazy please help

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The other day my computer was having graphic glitches, i went to update the drivers, but i have been getting svchost errors for 2 days now. My computer is slow, in games i am getting 0.1fps - 5.5fps, and firefox is slowing down. My computer wont reboot right, sometimes my wireless network doesn't work and then my screen will flicker several times and another taskbar with full items will show up. I have ran a check disk on my c: drive, i have also ran spybot and malwarebytes and nothing showed up. Here is a copy of Hijack this, can someone please help. Do I have a virus? what can i do? I cannot even do a system restore point, when i open it up, it doesn't let me choose anything before today to do a system restore. I checked and i do have let my computer do system restores. Im not handling this well. >.>

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:17:38 PM, on 1/29/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
E:\aawservice.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
E:\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
E:\WinZip\WZQKPICK.EXE
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
E:\SecondLife\SecondLife.exe
C:\Program Files\Linksys\WUSB100\WUSB100.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] E:\Winamp\winampa.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = E:\WinZip\WZQKPICK.EXE
O4 - Global Startup: Wireless Network Monitor.lnk = C:\Program Files\Linksys\WUSB100\WUSB100.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} (CPlayFirstDoggieDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…ash.1.0.0.6.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe (file missing)

–
End of file - 8669 bytes
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
My computer was having the svchost errors again yesterday upon booting. I looked in alot of forums and took some friends suggestions, prolly messed up my computer more. Anyways, it wasn't connecting to the internet, but got that figured out. It seems very sluggish at some points, my FPS is still low in games. I did get a "newer" video card (it is still older cheaper model) which has helped smooth out things a bit graphic wise. It sometimes beeps at me when i boot up, and the svchost errors will happen then it finally loads and yesterday windows kept crashing, but I've ran scans, stopped/started windows automatic update, i have a registry cleaner (regsupreme), did defrag and disk scans. But it seems quiet today and i reboot successfully with no svchost errors. Here is the reports. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 9:40:52.84 on Wed 02/04/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.259 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\Winamp\winampa.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE E:\WinZip\WZQKPICK.EXE C:\Program Files\Linksys\WUSB100\WUSB100.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe E:\SecondLife\SecondLife.exe C:\Documents and Settings\Jennifer\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - No File BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [WinampAgent] e:\winamp\winampa.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [nwiz] nwiz.exe /install mRun: [SoundMan] SOUNDMAN.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup StartupFolder: c:\docume~1\jennifer\startm~1\programs\startup\imvu.lnk - c:\documents and settings\jennifer\application data\imvuclient\IMVUClient.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Syncura Document Sharing Service.lnk.disabled StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - e:\winzip\WZQKPICK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb100\WUSB100.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\spybot~1\SDHelper.dll DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\jennifer\applic~1\mozilla\firefox\profiles\s6y15soe.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q= FF - plugin: c:\documents and settings\jennifer\application data\mozilla\firefox\profiles\s6y15soe.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp 07051001.dll FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: e:\divx web player\divx\divx content uploader\npUpload.dll FF - plugin: e:\divx web player\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: e:\divx web player\divx\divx web player\npdivx32.dll ============= SERVICES / DRIVERS =============== R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s [?] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s [?] R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632] S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -n "postgresql" -d "c:\program files\postgresql\8.0-beta2-dev3\data\" –> c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe [?] S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2005-2-24 44544] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;e:\sisoftware sandra lite 2009.sp2\rpcagentsrv.exe –> e:\sisoftware sandra lite 2009.sp2\RpcAgentSrv.exe [?] S4 Knmppotma;Knmppotma;c:\windows\system32\cmdl32.exe [2001-8-23 47104] =============== Created Last 30 ================ 2009-02-03 18:41 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll 2009-02-03 18:41 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2009-02-03 18:41 267,776 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-02-03 18:41 63,488 -c—— c:\windows\system32\dllcache\icardie.dll 2009-02-03 18:41 13,824 -c—— c:\windows\system32\dllcache\ieudinit.exe 2009-02-03 18:41 383,488 -c—— c:\windows\system32\dllcache\ieapfltr.dll 2009-02-03 18:41 2,455,488 -c—— c:\windows\system32\dllcache\ieapfltr.dat 2009-02-03 18:41 991,232 -c—— c:\windows\system32\dllcache\ieframe.dll.mui 2009-02-03 18:41 6,066,176 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-02-03 18:41 633,632 -c—— c:\windows\system32\dllcache\iexplore.exe 2009-02-03 18:23 54,156 a—h— c:\windows\QTFont.qfn 2009-02-03 18:23 1,409 a——- c:\windows\QTFont.for 2009-02-03 15:35 –d—– c:\program files\Linksys 2009-02-03 15:29 16,512 a——- c:\windows\system32\drivers\RAPIProtocol.sys 2009-02-03 15:29 21,361 a——- c:\windows\system32\drivers\AegisP.sys 2009-02-03 15:22 –d—– C:\Linksys Driver 2009-02-03 14:46 4,490,712 a——- C:\WindowsUpdateAgent20-x86.exe 2009-02-03 14:46 1,266,056 a——- C:\WindowsXP-KB927891.exe 2009-02-03 10:23 –d—– c:\program files\Realtek AC97 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-02-02 21:24 –d—– c:\docume~1\jennifer\applic~1\IMVU 2009-02-02 21:23 –d—– c:\docume~1\jennifer\applic~1\IMVUClient 2009-02-02 12:27 186,195 a——- c:\windows\system32\nvapps.xml 2009-02-02 12:27 –d—– c:\windows\nview 2009-02-02 10:46 453,152 a——- c:\windows\system32\nvudisp.exe 2009-02-02 10:46 18,070 a——- c:\windows\system32\nvdisp.nvu 2009-02-02 10:46 453,152 a——- c:\windows\system32\NVUNINST.EXE 2009-02-02 10:45 –d—– C:\NVIDIA 2009-02-02 10:42 552 a——- c:\windows\system32\d3d8caps.dat 2009-02-02 10:41 –d—– c:\program files\SystemRequirementsLab 2009-02-01 15:48 1,645,320 a——- c:\windows\system32\gdiplus.dll 2009-01-30 22:17 –d—– c:\windows\Logs 2009-01-30 15:49 –d—– c:\windows\system32\NtmsData 2009-01-30 03:31 23 a–sh— c:\windows\system32\feba1_g.dll 2009-01-30 03:31 23 a——- c:\windows\system32\cccfffec3_g.ocx 2009-01-30 03:31 –d—– c:\program files\RegSupreme 2009-01-30 02:31 –d—– c:\documents and settings\jennifer\Tracing 2009-01-30 02:30 –d—– c:\program files\Microsoft 2009-01-30 02:29 –d—– c:\program files\Windows Live SkyDrive 2009-01-30 02:21 –d—– c:\program files\common files\Windows Live 2009-01-29 17:29 –d—– c:\documents and settings\jennifer\.housecall6.6 2009-01-29 13:39 101,888 ac—— c:\windows\system32\dllcache\adpu160m.sys 2009-01-29 13:39 46,112 ac—— c:\windows\system32\dllcache\adptsf50.sys 2009-01-29 13:29 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll 2009-01-29 09:36 –d—– c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters 2009-01-29 09:35 –d—– c:\windows\system32\CatRoot_bak 2009-01-28 02:17 1,324 a——- c:\windows\system32\d3d9caps.dat 2009-01-28 01:58 0 a——- c:\windows\ativpsrm.bin 2009-01-15 08:19 1,253,376 a——- c:\windows\system32\NvPVEnc.ax ==================== Find3M ==================== 2008-12-11 06:57 333,184 a——- c:\windows\system32\drivers\srv.sys 2008-12-09 15:43 388,608 a——- c:\windows\system32\CF24313.exe 2008-12-09 03:18 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-04 10:36 3,396 a–sh— c:\windows\system32\dllcache\winsvcmgmnt.dll 2008-12-02 22:37 49,480 a——- c:\windows\system32\sirenacm.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll 2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll 2008-11-16 07:27 2,117,632 a——- c:\windows\system32\python25.dll 2008-11-16 07:27 339,968 a——- c:\windows\system32\pythoncom25.dll 2008-11-16 07:27 114,688 a——- c:\windows\system32\pywintypes25.dll 2006-08-14 22:28 24,096 ac—— c:\docume~1\jennifer\applic~1\GDIPFONTCACHEV1.DAT 2008-01-15 09:13 861 a–sh— c:\windows\system32\dllcache\aamonit.dll 2008-01-15 09:13 847,872 a–shr– c:\windows\system32\dllcache\libeay32.dll 2008-01-15 09:13 159,744 a–shr– c:\windows\system32\dllcache\ssleay32.dll 2008-01-15 09:13 64,000 a–shr– c:\windows\system32\dllcache\syschk32.dll 2008-01-15 09:13 488 a–shr– c:\windows\system32\dllcache\winsvcf.dll 2008-01-15 09:13 895 a–shr– c:\windows\system32\dllcache\winsvcn.dll 2007-07-31 17:42 55,296 ac-shr– c:\windows\system32\spool\drivers\raddrv.dll ============= FINISH: 9:42:05.03 ===============

Attachments:

Hi :)

Please open notepad, click Format and make sure "Word Wrap" is unchecked.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Please post a new DDS log in your next reply as well, only the first one (DDS.txt).

Thanks.
I'm sorry i've been really busy with RL and haven't had a chance to do this yet, I will try today. I just wanted to post this so the topic doesn't get closed!
No worries, that's not a problem. We are all busy at times. I only close topic if I haven't had a reply in 5 days. If you let me know that you are busy at the moment but haven't forgotten (like you did), I ill make exceptions. Thanks for letting me know :thumbup:
i will post new thread i think i'm coming up with another scan of darksma and virtemonde *sighs* i just got rid of trojans over the holidays. I'm sorry my computer has been so bad lately thank you
The Yahoo AntiVirus thing said i had ms juan/virtumonde/darksma again.
I am getting svchost errors, and weird msgs about my computer drive isn't ready, rebooting problems and amazing windows lag and it just started today getting popup windows on firefox.

I still am getting messages sent thru MSN virus, I cant format :| I need help please. I'm back online and ready to work on this again.

Here's the hijack this report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:07:16 AM, on 2/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Linksys\WUSB100\WUSB100.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
E:\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe
C:\SAM\SAMBC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page

= http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] E:\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [581ba7d8] rundll32.exe

"C:\WINDOWS\system32\qkstksqj.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program

Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: IMVU.lnk = C:\Documents and

Settings\Jennifer\Application Data\IMVUClient\IMVUClient.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program

Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program

Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program

Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Syncura Document Sharing

Service.lnk.disabled
O4 - Global Startup: Wireless Network Monitor.lnk = C:\Program

Files\Linksys\WUSB100\WUSB100.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control

Panel present
O8 - Extra context menu item: &Yahoo;! Search -

file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; -

file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program

Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program

Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

E:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy

Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

E:\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP:

c:\windows\system32\nwprovau.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec

AntiVirus scanner) -

http://security.symantec.com/sscv6/SharedC…/vc/bin/AvSniff.

cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -

http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec

RuFSI Utility Class) -

http://security.symantec.com/sscv6/SharedC…common/bin/cabs

a.cab
O16 - DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96}

(CPlayFirstDoggieDashControl Object) -

http://aolsvc.aol.com/onlinegames/free-tri…ie-dash/DoggieD

ash.1.0.0.6.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} -
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…tsPAClient.cab5

6907.cab
O18 - Protocol: skype4com -

{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: mwhsnr.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program

Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance

(FirebirdGuardianDefaultInstance) - The Firebird Project -

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance

(FirebirdServerDefaultInstance) - The Firebird Project -

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) -

Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA

Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown

owner - C:\Program

Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service

(SandraAgentSrv) - SiSoftware - E:\SiSoftware Sandra Lite

2009.SP2\RpcAgentSrv.exe

–
End of file - 6735 bytes

Here is the DDS report:


DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 2:30:49.26 on Mon 02/16/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.113 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Linksys\WUSB100\WUSB100.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
E:\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
E:\SUPERAntiSpyware.exe
C:\Documents and Settings\Jennifer\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {2ca5ae27-da3c-431b-96e9-498fad59f8f8} - c:\windows\system32\cbXqPFVm.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - No File
BHO: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\AWTQOOHX.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
BHO: {b7ec599f-9b66-c228-72f4-6325b5ceebce}: {ecbeec5b-5236-4f27-822c-66b9f995ce7b} - c:\windows\system32\MWHSNR.DLL
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [SUPERAntiSpyware] E:\SUPERAntiSpyware.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [WinampAgent] e:\winamp\winampa.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [581ba7d8] rundll32.exe "c:\windows\system32\qkstksqj.dll",b
StartupFolder: c:\docume~1\jennifer\startm~1\programs\startup\imvu.lnk - c:\documents and settings\jennifer\application data\imvuclient\IMVUClient.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Syncura Document Sharing Service.lnk.disabled
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb100\WUSB100.exe
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
IE: &Yahoo;! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary; - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\spybot~1\SDHelper.dll
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D}
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - E:\SASWINLO.dll
Notify: awtqoOHx - awtqoOHx.dll
AppInit_DLLs: mwhsnr.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\AWTQOOHX.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - E:\SASSEH.DLL
LSA: Authentication Packages = msv1_0 c:\windows\system32\cbXqPFVm

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jennifer\applic~1\mozilla\firefox\profiles\s6y15soe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-amo&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs;=1≻=2&f;=web&vernum;=1.0&uid;=&did;=f8d4a70c-98e2-4081-901d-01bf93043ede&q;=
FF - plugin: c:\documents and settings\jennifer\application data\mozilla\firefox\profiles\s6y15soe.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07051001.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: e:\divx web player\divx\divx content uploader\npUpload.dll
FF - plugin: e:\divx web player\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: e:\divx web player\divx\divx web player\npdivx32.dll

============= SERVICES / DRIVERS ===============

R1 SASDIFSV;SASDIFSV;E:\sasdifsv.sys [2009-1-15 8944]
R1 SASKUTIL;SASKUTIL;E:\SASKUTIL.SYS [2009-1-15 55024]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s [?]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s [?]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632]
R3 SASENUM;SASENUM;E:\SASENUM.SYS [2009-1-15 7408]
S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -n "postgresql" -d "c:\program files\postgresql\8.0-beta2-dev3\data\" –> c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe [?]
S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2005-2-24 44544]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;e:\sisoftware sandra lite 2009.sp2\RpcAgentSrv.exe [2009-2-15 98488]
S4 Aiangvcs;Aiangvcs;c:\windows\system32\perfmon.exe [2001-8-23 15872]

=============== Created Last 30 ================

2009-02-16 02:27 –d—– c:\docume~1\jennifer\applic~1\SUPERAntiSpyware.com
2009-02-15 16:36 129,024 a——- c:\windows\system32\mwhsnr.dll
2009-02-15 16:36 129,024 a——- c:\windows\system32\ojcpehfl.dll
2009-02-15 16:34 1,583,467 —sh— c:\windows\system32\jqsktskq.ini
2009-02-15 16:34 72,704 a——- c:\windows\system32\qkstksqj.dll
2009-02-15 16:33 32,922 a–sh— c:\windows\system32\mVFPqXbc.ini2
2009-02-15 16:33 32,922 a–sh— c:\windows\system32\mVFPqXbc.ini
2009-02-15 16:33 302,592 a——- c:\windows\system32\cbXqPFVm.dll
2009-02-15 16:28 48,128 a——- c:\windows\system32\ljJDUkkh.dll
2009-02-15 16:28 36,352 a——- c:\windows\system32\awtqoOHx.dll
2009-02-09 07:30 54,156 a—h— c:\windows\QTFont.qfn
2009-02-09 07:30 1,409 a——- c:\windows\QTFont.for
2009-02-07 16:06 206,793 a——- c:\windows\system32\nvapps.nvb
2009-02-03 18:41 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll
2009-02-03 18:41 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-03 18:41 267,776 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-02-03 18:41 63,488 -c—— c:\windows\system32\dllcache\icardie.dll
2009-02-03 18:41 13,824 -c—— c:\windows\system32\dllcache\ieudinit.exe
2009-02-03 18:41 383,488 -c—— c:\windows\system32\dllcache\ieapfltr.dll
2009-02-03 18:41 2,455,488 -c—— c:\windows\system32\dllcache\ieapfltr.dat
2009-02-03 18:41 991,232 -c—— c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-03 18:41 6,066,176 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-02-03 18:41 633,632 -c—— c:\windows\system32\dllcache\iexplore.exe
2009-02-03 15:35 –d—– c:\program files\Linksys
2009-02-03 15:29 16,512 a——- c:\windows\system32\drivers\RAPIProtocol.sys
2009-02-03 15:29 21,361 a——- c:\windows\system32\drivers\AegisP.sys
2009-02-03 15:22 –d—– C:\Linksys Driver
2009-02-03 14:46 4,490,712 a——- C:\WindowsUpdateAgent20-x86.exe
2009-02-03 14:46 1,266,056 a——- C:\WindowsXP-KB927891.exe
2009-02-03 10:23 –d—– c:\program files\Realtek AC97
2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\Norton
2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-02-02 12:27 200,411 a——- c:\windows\system32\nvapps.xml
2009-02-02 12:27 –d—– c:\windows\nview
2009-02-02 10:46 453,152 a——- c:\windows\system32\nvudisp.exe
2009-02-02 10:46 18,725 a——- c:\windows\system32\nvdisp.nvu
2009-02-02 10:46 453,152 a——- c:\windows\system32\NVUNINST.EXE
2009-02-02 10:45 –d—– C:\NVIDIA
2009-02-02 10:42 552 a——- c:\windows\system32\d3d8caps.dat
2009-02-02 10:41 –d—– c:\program files\SystemRequirementsLab
2009-02-01 15:48 1,645,320 a——- c:\windows\system32\gdiplus.dll
2009-01-30 22:17 –d—– c:\windows\Logs
2009-01-30 15:49 –d—– c:\windows\system32\NtmsData
2009-01-30 03:31 23 a–sh— c:\windows\system32\feba1_g.dll
2009-01-30 03:31 23 a——- c:\windows\system32\cccfffec3_g.ocx
2009-01-30 03:31 –d—– c:\program files\RegSupreme
2009-01-30 02:31 –d—– c:\documents and settings\jennifer\Tracing
2009-01-30 02:30 –d—– c:\program files\Microsoft
2009-01-30 02:29 –d—– c:\program files\Windows Live SkyDrive
2009-01-30 02:21 –d—– c:\program files\common files\Windows Live
2009-01-29 17:29 –d—– c:\documents and settings\jennifer\.housecall6.6
2009-01-29 13:39 101,888 ac—— c:\windows\system32\dllcache\adpu160m.sys
2009-01-29 13:39 46,112 ac—— c:\windows\system32\dllcache\adptsf50.sys
2009-01-29 13:29 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll
2009-01-29 09:36 –d—– c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters
2009-01-29 09:35 –d—– c:\windows\system32\CatRoot_bak
2009-01-28 02:17 1,324 a——- c:\windows\system32\d3d9caps.dat
2009-01-28 01:58 0 a——- c:\windows\ativpsrm.bin

==================== Find3M ====================

2008-12-09 15:43 388,608 a——- c:\windows\system32\CF24313.exe
2008-12-09 03:18 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-04 10:36 3,396 a–sh— c:\windows\system32\dllcache\winsvcmgmnt.dll
2008-12-02 22:37 49,480 a——- c:\windows\system32\sirenacm.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll
2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll
2006-08-14 22:28 24,096 ac—— c:\docume~1\jennifer\applic~1\GDIPFONTCACHEV1.DAT
2008-01-15 09:13 861 a–sh— c:\windows\system32\dllcache\aamonit.dll
2008-01-15 09:13 847,872 a–shr– c:\windows\system32\dllcache\libeay32.dll
2008-01-15 09:13 159,744 a–shr– c:\windows\system32\dllcache\ssleay32.dll
2008-01-15 09:13 64,000 a–shr– c:\windows\system32\dllcache\syschk32.dll
2008-01-15 09:13 488 a–shr– c:\windows\system32\dllcache\winsvcf.dll
2008-01-15 09:13 895 a–shr– c:\windows\system32\dllcache\winsvcn.dll
2007-07-31 17:42 55,296 ac-shr– c:\windows\system32\spool\drivers\raddrv.dll

============= FINISH: 2:33:24.85 ===============

The Super-antispyware (free edition) report:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/16/2009 at 03:34 AM

Application Version : 4.25.1012

Core Rules Database Version : 3760
Trace Rules Database Version: 1722

Scan type : Quick Scan
Total Scan Time : 00:57:08

Memory items scanned : 415
Memory threats detected : 4
Registry items scanned : 482
Registry threats detected : 69
File items scanned : 10231
File threats detected : 10

Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\MWHSNR.DLL
C:\WINDOWS\SYSTEM32\MWHSNR.DLL

Trojan.Vundo-Variant/Small-GEN
C:\WINDOWS\SYSTEM32\AWTQOOHX.DLL
C:\WINDOWS\SYSTEM32\AWTQOOHX.DLL
C:\WINDOWS\SYSTEM32\CBXQPFVM.DLL
C:\WINDOWS\SYSTEM32\CBXQPFVM.DLL
C:\WINDOWS\SYSTEM32\LJJDUKKH.DLL

Adware.Fecati/Resident
C:\WINDOWS\SYSTEM32\QKSTKSQJ.DLL
C:\WINDOWS\SYSTEM32\QKSTKSQJ.DLL

Trojan.Vundo-Variant/NextGen
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2CA5AE27-DA3C-431B-96E9-498FAD59F8F8}
HKCR\CLSID\{2CA5AE27-DA3C-431B-96E9-498FAD59F8F8}
HKCR\CLSID\{2CA5AE27-DA3C-431B-96E9-498FAD59F8F8}\InprocServer32
HKCR\CLSID\{2CA5AE27-DA3C-431B-96E9-498FAD59F8F8}\InprocServer32#ThreadingModel
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\awtqoOHx

Unclassified.Unknown Origin
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}

Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecbeec5b-5236-4f27-822c-66b9f995ce7b}
HKCR\CLSID\{ECBEEC5B-5236-4F27-822C-66B9F995CE7B}
HKCR\CLSID\{ECBEEC5B-5236-4F27-822C-66B9F995CE7B}\InprocServer32
HKCR\CLSID\{ECBEEC5B-5236-4F27-822C-66B9F995CE7B}\InprocServer32#ThreadingModel
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ECBEEC5B-5236-4F27-822C-66B9F995CE7B}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ECBEEC5B-5236-4F27-822C-66B9F995CE7B}

Adware.Tracking Cookie
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt
C:\Documents and Settings\Jennifer\Cookies\kishkoway@wmvmedialease[1].txt

Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\FCOVM
HKLM\SOFTWARE\Microsoft\RemoveRP
HKLM\SOFTWARE\Microsoft\MS Juan
HKLM\SOFTWARE\Microsoft\MS Juan#RID
HKLM\SOFTWARE\Microsoft\MS Juan\DJZERO
HKLM\SOFTWARE\Microsoft\MS Juan\DJZERO#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\DJZERO#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\DJZERO#CNT
HKLM\SOFTWARE\Microsoft\MS Juan\JKWL
HKLM\SOFTWARE\Microsoft\MS Juan\JKWL\adware.vundo/variant
HKLM\SOFTWARE\Microsoft\MS Juan\JKWL\adware.vundo/variant#LU
HKLM\SOFTWARE\Microsoft\MS Juan\JKWL\adware.vundo/variant#CT
HKLM\SOFTWARE\Microsoft\MS Juan\JKWL\adware.vundo/variant#LT
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan#CNT
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan#LBL
HKLM\SOFTWARE\Microsoft\MS Juan\metajuan#MN
HKLM\SOFTWARE\Microsoft\MS Juan\meta_mg
HKLM\SOFTWARE\Microsoft\MS Juan\meta_mg#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\meta_mg#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\meta_mg#CNT
HKLM\SOFTWARE\Microsoft\MS Juan\profiling4
HKLM\SOFTWARE\Microsoft\MS Juan\profiling4#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\profiling4#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\profiling4#CNT
HKLM\SOFTWARE\Microsoft\MS Juan\superjuan
HKLM\SOFTWARE\Microsoft\MS Juan\superjuan#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\superjuan#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\superjuan#CNT
HKLM\SOFTWARE\Microsoft\MS Juan\TrackDJuan
HKLM\SOFTWARE\Microsoft\MS Juan\TrackDJuan#LTM
HKLM\SOFTWARE\Microsoft\MS Juan\TrackDJuan#CDY
HKLM\SOFTWARE\Microsoft\MS Juan\TrackDJuan#CNT
HKLM\SOFTWARE\Microsoft\contim
HKLM\SOFTWARE\Microsoft\contim#SysShell
HKLM\SOFTWARE\Microsoft\MS Track System
HKLM\SOFTWARE\Microsoft\MS Track System#Click1
HKLM\SOFTWARE\Microsoft\MS Track System#Uqs
HKLM\SOFTWARE\Microsoft\rdfa
HKLM\SOFTWARE\Microsoft\rdfa#F
HKLM\SOFTWARE\Microsoft\rdfa#N

Rogue.Component/Trace
HKLM\Software\Microsoft\581BB556
HKLM\Software\Microsoft\581BB556#581bb556
HKLM\Software\Microsoft\581BB556#Version
HKLM\Software\Microsoft\581BB556#581b18d6
HKLM\Software\Microsoft\581BB556#581b7133
HKU\S-1-5-21-823518204-507921405-725345543-1003\Software\Microsoft\CS41275
HKU\S-1-5-21-823518204-507921405-725345543-1003\Software\Microsoft\FIAS4018

Trojan.Unclassified
C:\WINDOWS\SYSTEM32\MPFSERVICEFAILURECOUNT.TXT

Adware.Vundo/Variant-S129
C:\WINDOWS\SYSTEM32\OJCPEHFL.DLL

i clicked next on the anti-super spyware thing and it wanted me to reboot my computer :|
so i rebooted

got a .dll error in something

ok i'm gonna run spybot S&D;

and i need a free anti virus
i tried that norton 360 demo, but i uninstalled it

:pullhair:
Hi,

No need to start a new thread then, we can keep it all in one place.

I notice you have run SUPERAntiSpyware and that has cleared up some Malware. Please do the following and we will see this one through.

Hi :)

Please open notepad, click Format and make sure "Word Wrap" is unchecked.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Please post a new DDS log in your next reply as well, only the first one (DDS.txt). Make sure you do this after the other steps, so it is nice and fresh.

Thanks.
Results of Malware byte scan: Malwarebytes' Anti-Malware 1.34 Database version: 1765 Windows 5.1.2600 Service Pack 2 2/16/2009 2:13:19 PM mbam-log-2009-02-16 (14-13-19).txt Scan type: Full Scan (C:\|E:\|) Objects scanned: 188218 Time elapsed: 2 hour(s), 39 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-16 14:54:09
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT \??\E:\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEB6BDF20]

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!pfnUnmarshallRoutines + FFF760D1 77E71379 451 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!pfnUnmarshallRoutines + FFF76298 77E71540 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!pfnUnmarshallRoutines + FFF762AC 77E71554 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!pfnUnmarshallRoutines + FFF762C0 77E71568 196 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!pfnUnmarshallRoutines + FFF76388 77E71630 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeAlignment + 5 77E7165D 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeAlignment + B8 77E71710 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeAlignment + BB 77E71713 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeBufferSize + 1 77E71719 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeBufferSize + B8 77E717D0 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeBufferSize + BB 77E717D3 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeMemorySize + 1 77E717D9 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeMemorySize + B8 77E71890 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeMemorySize + BB 77E71893 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeMemorySize + C0 77E71898 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!SimpleTypeMemorySize + C4 77E7189C 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFlags + 12 77E75D4A 24 Bytes [ 52, 70, 63, 42, 69, 6E, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFlags + 2B 77E75D63 22 Bytes [ 52, 70, 63, 42, 69, 6E, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFlags + 42 77E75D7A 19 Bytes [ 52, 70, 63, 42, 69, 6E, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFlags + 56 77E75D8E 19 Bytes [ 52, 70, 63, 42, 69, 6E, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFlags + 6A 77E75DA2 15 Bytes [ 52, 70, 63, 42, 69, 6E, 64, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreate + 8 77E7625C 194 Bytes [ 74, 00, 52, 70, 63, 4D, 67, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreate + CB 77E7631F 107 Bytes [ 52, 70, 63, 4E, 65, 74, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreate + 137 77E7638B 138 Bytes [ 6E, 71, 46, 6E, 00, 52, 70, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreate + 1C2 77E76416 167 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreate + 26A 77E764BE 158 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheFree + A 77E76652 22 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheFree + 21 77E76669 58 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheFree + 5C 77E766A4 36 Bytes [ 72, 6F, 74, 73, 65, 71, 49, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheFree + 81 77E766C9 43 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheFree + AD 77E766F5 44 Bytes [ 52, 70, 63, 53, 65, 72, 76, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFree + C 77E785DA 9 Bytes [ 00, 00, 88, 01, 00, 00, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFree + 16 77E785E4 7 Bytes [ E0, 00, 00, 00, 24, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFree + 1E 77E785EC 15 Bytes [ 14, 00, 00, 00, D0, 16, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFree + 2E 77E785FC 43 Bytes [ 18, C9, EE, 77, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFree + 5A 77E78628 20 Bytes JMP 669CDEA4
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRevertToSelf + 7 77E78684 112 Bytes [ 88, 01, 00, 00, 98, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAllocate + 37 77E786F5 53 Bytes [ D5, ED, 77, 24, 05, EE, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAllocate + 6E 77E7872C 6 Bytes [ E0, 00, 00, 00, E0, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAllocate + 76 77E78734 7 Bytes [ 80, 00, 00, 00, 06, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAllocate + 7F 77E7873D 59 Bytes [ 01, 00, 00, 00, 04, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAllocate + BC 77E7877A 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOleFree + 22 77E7884F 23 Bytes [ 02, 00, 00, 50, FF, D7, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOleFree + 3A 77E78867 4 Bytes [ 85, 79, EC, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOleFree + 3F 77E7886C 7 Bytes [ 89, 5D, DC, 8D, 9E, 2C, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOleFree + 47 77E78874 19 Bytes [ 00, 53, FF, 15, 5C, 11, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOleFree + 5B 77E78888 31 Bytes [ 0F, 85, A3, F3, FF, FF, 83, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcGetBuffer + 21 77E7920A 14 Bytes [ 7D, 08, 39, 07, 75, 1A, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcGetBuffer + 30 77E79219 72 Bytes [ 10, E7, 77, 89, 06, F7, D8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcGetBuffer + 79 77E79262 123 Bytes [ 7F, 66, 39, 48, 1E, 75, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcGetBuffer + F5 77E792DE 119 Bytes [ FF, 56, 8B, F1, 8D, 46, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitializeNew + 28 77E79357 170 Bytes [ F6, 45, 08, 01, 74, 07, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitialize + 99 77E79402 4 Bytes [ C3, 83, 65, DC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitialize + 9E 77E79407 4 Bytes [ 8D, 86, 2C, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitialize + B1 77E7941A 48 Bytes [ 8B, FF, 57, 33, C0, 8B, F9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitialize + E2 77E7944B 59 Bytes CALL B7E79453
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientInitialize + 11E 77E79487 176 Bytes [ 8B, 75, 08, 85, F6, 8B, D9, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetBuffer + D 77E7980A 35 Bytes [ 00, 00, 3B, 77, EF, 77, 65, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetBuffer + 31 77E7982E 16 Bytes [ FF, 55, 8B, EC, 5D, FF, 25, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetBuffer + 44 77E79841 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetBuffer + 4A 77E79847 80 Bytes [ 45, 08, 56, 8B, F1, 66, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFreeBuffer + 14 77E79898 3 Bytes [ 01, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFreeBuffer + 18 77E7989C 4 Bytes [ 73, FC, FF, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFreeBuffer + 1E 77E798A2 3 Bytes [ 89, 86, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFreeBuffer + 22 77E798A6 48 Bytes [ 00, 00, 0F, 85, 23, 3D, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFreeBuffer + 55 77E798D9 61 Bytes [ 8B, FF, 56, 8D, 71, 54, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatFree + 2D 77E79927 22 Bytes [ 8B, 1B, FF, 45, FC, E9, D0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatFree + 44 77E7993E 2 Bytes [ 1E, FB ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatFree + 4A 77E79944 67 Bytes [ 59, 59, 0F, 84, 73, 3D, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreeBuffer + 2D 77E79988 75 Bytes JMP 77E8759D C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreeBuffer + D2 77E79A2D 70 Bytes [ 8D, 44, 7F, 09, 8D, 04, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreeBuffer + 119 77E79A74 13 Bytes [ 8B, 00, 89, 02, 8B, 45, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreeBuffer + 127 77E79A82 13 Bytes [ 8D, 43, 50, 50, FF, 15, 58, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreeBuffer + 135 77E79A90 18 Bytes [ C0, 74, 82, 47, 89, 38, 83, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetTypeFlags + 166 77E79C12 31 Bytes [ F7, DA, 89, 01, 89, 51, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetTypeFlags + 186 77E79C32 2 Bytes [ 53, 89 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetTypeFlags + 18A 77E79C36 15 Bytes [ FF, D7, FF, 46, 24, 83, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetTypeFlags + 1CE 77E79C7A 8 Bytes [ C8, FF, 52, 04, E9, 4B, FD, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetTypeFlags + 1D7 77E79C83 32 Bytes JMP 77E8319F C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCorrelationPass + C9 77E7A016 23 Bytes [ 57, FF, 15, 5C, 13, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCorrelationPass + E2 77E7A02F 19 Bytes [ 8B, 45, 08, 89, 46, 08, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCorrelationPass + F6 77E7A043 69 Bytes [ 15, 58, 13, E7, 77, FF, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCorrelationPass + 147 77E7A094 71 Bytes [ 15, 74, 11, E7, 77, E9, 80, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCorrelationPass + 18F 77E7A0DC 24 Bytes [ 15, 5C, 11, E7, 77, A1, 14, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CheckVerificationTrailer 77E7A13C 45 Bytes [ 90, 90, 90, 6A, 10, 68, 68, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CheckVerificationTrailer + 2F 77E7A16B 37 Bytes JMP EA615A77
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CheckVerificationTrailer + 55 77E7A191 45 Bytes [ 5E, 08, 81, E3, 48, 20, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CheckVerificationTrailer + 83 77E7A1BF 18 Bytes [ 50, 34, 85, C0, 75, 18, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CheckVerificationTrailer + 96 77E7A1D2 65 Bytes [ FF, 75, 0C, 8B, 06, 8B, CE, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitialize + 12 77E7A2B7 26 Bytes [ 0F, B7, 02, 03, 45, F4, 84, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitialize + 2D 77E7A2D2 114 Bytes [ E7, 77, 8B, 55, F8, 8B, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitialize + A0 77E7A345 19 Bytes [ 00, 00, 8B, 46, 2C, 85, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitialize + B4 77E7A359 30 Bytes [ 5E, 0F, 87, 5F, 74, 03, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitialize + D3 77E7A378 11 Bytes [ 0E, 89, 48, 18, 8B, 4D, 14, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOutInit + 2B 77E7A7A2 4 Bytes [ 82, A2, 1B, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOutInit + 30 77E7A7A7 20 Bytes [ 8B, 45, 18, 89, 30, 33, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOutInit + 45 77E7A7BC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOutInit + 4B 77E7A7C2 7 Bytes [ 00, 00, 02, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrOutInit + 54 77E7A7CB 30 Bytes [ 00, 04, 00, 00, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrAllocate + 7 77E7A9FE 105 Bytes [ 0F, B6, 48, 04, 0F, B6, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrAllocate + 71 77E7AA68 7 Bytes [ 00, 00, 00, 0F, 85, 73, 06 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrAllocate + 79 77E7AA70 7 Bytes [ 00, 83, 4D, FC, FF, E8, 0D ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrAllocate + A6 77E7AA9D 9 Bytes [ F6, C1, 28, 75, AA, E9, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrAllocate + B0 77E7AAA7 31 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSendReceive + C 77E7AB0B 19 Bytes [ 75, 10, 8B, 0B, 8B, 01, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSendReceive + 20 77E7AB1F 2 Bytes [ F8, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSendReceive + 23 77E7AB22 2 Bytes [ 00, 56 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSendReceive + 26 77E7AB25 43 Bytes [ 15, 60, 11, E7, 77, 8B, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSendReceive + 52 77E7AB51 45 Bytes [ 8B, 80, 1C, 0F, 00, 00, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeNew + 24 77E7AB7F 4 Bytes [ 00, 8B, 87, FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeNew + 29 77E7AB84 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeNew + 2B 77E7AB86 24 Bytes [ 8B, 4F, 6C, 3B, C1, 0F, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeNew + 44 77E7AB9F 44 Bytes [ 83, 7D, FC, 00, 0F, 85, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeNew + 71 77E7ABCC 15 Bytes [ 40, 04, 8B, 4D, 08, 56, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcImpersonateClient + 6 77E7ABF4 56 Bytes [ 60, 60, FB, 39, 18, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcImpersonateClient + 5E 77E7AC4C 45 Bytes [ 48, 14, 85, C9, 0F, 85, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRevertToSelfEx + 25 77E7AC9B 273 Bytes [ 39, 41, 14, 0F, 94, C0, C3, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRevertToSelfEx + 137 77E7ADAD 11 Bytes [ 56, 8B, B3, C4, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpMemoryIncrement + 4 77E7ADB9 3 Bytes [ 46, 28, 57 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpMemoryIncrement + 8 77E7ADBD 27 Bytes [ 7E, 14, 89, 45, FC, 76, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpMemoryIncrement + 24 77E7ADD9 59 Bytes [ E0, 01, 66, 85, C0, 74, 09, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpMemoryIncrement + 60 77E7AE15 9 Bytes [ 80, 66, 69, 03, 00, 83, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpMemoryIncrement + 6A 77E7AE1F 96 Bytes [ 85, 68, 69, 03, 00, 3D, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructUnmarshall + 4A 77E7B270 19 Bytes [ 4E, 04, 2B, 48, 08, 5E, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructUnmarshall + 5E 77E7B284 8 Bytes [ 90, 90, 90, 90, FF, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructUnmarshall + 68 77E7B28E 180 Bytes [ 00, 00, 98, 6F, EF, 77, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructUnmarshall + 123 77E7B349 97 Bytes [ FF, 3B, C3, 5B, 0F, 85, 91, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerFree + 33 77E7B3AB 4 Bytes [ 85, 8B, 7F, 03 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerFree + 38 77E7B3B0 11 Bytes [ 0F, B7, 57, 02, 03, 53, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerFree + 44 77E7B3BC 88 Bytes [ 07, A8, 40, 0F, 85, 0D, FB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerFree + 9D 77E7B415 54 Bytes [ FF, 45, FC, 8B, 45, FC, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerFree + D4 77E7B44C 44 Bytes [ C9, C2, 04, 00, 90, 90, 90, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerMarshall + 6 77E7B4AC 58 Bytes [ 43, 28, A8, 03, 0F, 85, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerBufferSize + 6 77E7B4E7 21 Bytes [ 45, FC, 83, 4F, 70, 40, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerBufferSize + 1C 77E7B4FD 16 Bytes [ 08, 0F, 85, DF, 7E, 03, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerBufferSize + 2D 77E7B50E 13 Bytes [ 8B, 46, 08, F6, 40, 04, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerUnmarshall + 9 77E7B51C 1 Byte [ 4E ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerUnmarshall + B 77E7B51E 32 Bytes [ 0F, B6, 49, 07, 8B, 47, 70, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerUnmarshall + 2C 77E7B53F 25 Bytes [ 80, 7D, 0B, 00, 5F, 5E, 5B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerUnmarshall + 46 77E7B559 5 Bytes [ 84, BE, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerUnmarshall + 4C 77E7B55F 1 Byte [ 04 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeMarshall + 17 77E7B58C 19 Bytes [ 45, FC, 89, 3B, 0F, B7, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeMarshall + 2B 77E7B5A0 130 Bytes [ F3, AB, 8B, CA, 83, E1, 03, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeMarshall + AE 77E7B623 96 Bytes [ 45, F8, 83, C1, 06, 3B, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeMarshall + 10F 77E7B684 19 Bytes [ 15, 5C, 11, E7, 77, 83, 7B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeMarshall + 123 77E7B698 49 Bytes [ 75, C8, 8D, 45, D0, 50, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructBufferSize 77E7B6CD 65 Bytes [ 90, 90, 90, FF, FF, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructBufferSize + 42 77E7B70F 29 Bytes [ 32, 8B, 01, 8B, 04, B0, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructBufferSize + 60 77E7B72D 14 Bytes [ 00, 00, 00, 90, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructBufferSize + 6F 77E7B73C 47 Bytes [ 75, 08, 83, 7E, 20, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructBufferSize + D8 77E7B7A5 1 Byte [ 03 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructFree + 6 77E7B90D 173 Bytes [ 06, 0F, B6, CA, 83, E9, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructFree + B4 77E7B9BB 6 Bytes JMP 77E83069 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructFree + BB 77E7B9C2 88 Bytes [ 56, 48, 85, C0, 0F, 84, 6D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructFree + 114 77E7BA1B 151 Bytes [ 57, 8B, 7D, 10, 57, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayMarshall + 4F 77E7BAB3 20 Bytes [ 8D, 46, 20, 83, 38, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayMarshall + 64 77E7BAC8 142 Bytes [ 5F, 5E, 5D, C2, 08, 00, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayUnmarshall 77E7BB5A 7 Bytes [ 90, 8B, FF, 55, 8B, EC, 53 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayUnmarshall + 8 77E7BB62 80 Bytes [ 5D, 10, 56, 8B, 75, 08, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayUnmarshall + 59 77E7BBB3 96 Bytes [ 0F, 84, D8, EF, FF, FF, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayFree + 3A 77E7BC14 16 Bytes [ 8B, 75, 08, 85, F6, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayFree + 4E 77E7BC28 17 Bytes [ 23, 8E, 02, 00, 8B, 70, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayFree + 60 77E7BC3A 310 Bytes [ CE, FF, 90, 80, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayFree + 197 77E7BD71 47 Bytes [ 00, 00, 00, 95, 65, ED, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayFree + 1C9 77E7BDA3 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqTransportType + C 77E7CABA 27 Bytes [ 00, 00, 74, 0B, 53, 56, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqTransportType + 28 77E7CAD6 65 Bytes [ 46, 01, 8B, 57, 04, 03, D0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqTransportType + 6A 77E7CB18 47 Bytes [ 83, C6, 08, F6, 47, 70, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqTransportType + 9A 77E7CB48 68 Bytes [ C8, 83, E1, 03, F3, A4, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqTransportType + DF 77E7CB8D 71 Bytes [ 7D, 0C, 75, 2D, 33, D2, 39, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshall2 + 61 77E7D2EE 43 Bytes [ A1, AC, B2, EF, 77, 83, A5, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshall2 + 8D 77E7D31A 39 Bytes [ 8D, 47, 38, 89, 46, 08, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshall2 + B5 77E7D342 14 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshall2 + C4 77E7D351 69 Bytes [ 56, 8B, F1, 8B, 8E, 98, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshall2 + 113 77E7D3A0 32 Bytes [ 51, 51, 8B, 45, 14, 83, 20, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewUnmarshall + 23 77E7D6B4 113 Bytes [ 8B, 40, 08, 85, C0, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewUnmarshall + 95 77E7D726 45 Bytes [ 03, 85, C0, 0F, 85, B0, 60, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewUnmarshall + C4 77E7D755 21 Bytes [ 8B, 01, 85, C0, 0F, 85, 9D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewUnmarshall + DA 77E7D76B 52 Bytes [ 56, 57, 8B, 7D, 08, BB, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewUnmarshall + 10F 77E7D7A0 76 Bytes [ 83, 60, 04, 00, 8B, 86, A0, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextBinding + 2B 77E7D9FE 3 Bytes [ FF, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextBinding + 31 77E7DA04 110 Bytes [ 8B, FF, 55, 8B, EC, 56, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextBinding + A0 77E7DA73 59 Bytes [ 84, 00, 00, 00, 85, FF, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextBinding + DC 77E7DAAF 48 Bytes [ FF, 55, 8B, EC, 83, 3D, DC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextUnmarshall + 13 77E7DAE0 6 Bytes [ F7, 46, 08, 48, 20, 20 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextUnmarshall + 1A 77E7DAE7 5 Bytes [ FF, 75, 0C, 8B, 06 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextUnmarshall + 20 77E7DAED 12 Bytes [ CE, 0F, 84, 01, BD, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextUnmarshall + 2D 77E7DAFA 19 Bytes [ 5E, 5D, C2, 08, 00, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRCContextUnmarshall + 41 77E7DB0E 37 Bytes [ 04, 00, 00, 00, 33, C0, 5D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewMarshall + 11 77E7DC1B 9 Bytes [ 8B, 90, 00, 00, 00, 66, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewMarshall + 1B 77E7DC25 23 Bytes [ 83, D8, 00, 00, 00, 3B, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewMarshall + 33 77E7DC3D 28 Bytes [ 47, 08, 89, 45, 08, 8B, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerContextNewMarshall + 50 77E7DC5A 44 Bytes [ 00, 00, FF, 70, 78, FF, 15, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextMarshall2 + 1F 77E7DC87 27 Bytes [ 00, 80, 78, 18, 04, 0F, 84, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextMarshall2 + 3C 77E7DCA4 39 Bytes [ 80, 78, 18, 10, 0F, 84, E1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextMarshall2 + 65 77E7DCCD 90 Bytes [ F0, 0F, 85, CD, 06, 03, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextMarshall2 + C1 77E7DD29 60 Bytes [ 00, 8B, 91, BC, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextMarshall2 + FF 77E7DD67 2 Bytes [ 18, 13 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingCopy + 19 77E7DF43 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingCopy + 1B 77E7DF45 14 Bytes [ 89, 78, 04, 8B, 86, 90, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingCopy + 2B 77E7DF55 60 Bytes [ 86, 90, 00, 00, 00, 66, C7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingCopy + 68 77E7DF92 91 Bytes [ 83, C0, 78, 50, FF, 15, 5C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingCopy + C4 77E7DFEE 30 Bytes [ FF, 59, 33, C9, 3B, C1, 6A, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStatsVectorFree + 12 77E7E350 27 Bytes [ 00, 83, 7D, 14, 00, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStatsVectorFree + 2E 77E7E36C 1 Byte [ 14 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStatsVectorFree + 30 77E7E36E 25 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStatsVectorFree + 4A 77E7E388 9 Bytes [ C0, 0F, 85, 7C, 23, 03, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStatsVectorFree + 54 77E7E392 36 Bytes [ 5D, C2, 04, 00, 90, 90, 90, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingW + 13 77E7E55B 27 Bytes [ FF, FF, FF, A8, 03, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingW + 2F 77E7E577 18 Bytes [ 85, DB, 74, 03, 83, 23, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingW + 43 77E7E58B 9 Bytes [ 33, C0, 5F, 5E, 5B, C9, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseW 77E7E596 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseW + 4 77E7E59A 89 Bytes [ FF, 55, 8B, EC, 51, A1, AC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseW + 69 77E7E5FF 72 Bytes [ FF, 85, C0, 0F, 84, 80, 07, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseW + B2 77E7E648 57 Bytes [ 83, 60, 64, 00, 8B, 45, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseW + ED 77E7E683 12 Bytes JMP EAF98C77
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingW + C1 77E7E766 26 Bytes [ 20, 0F, 84, 99, 53, 02, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingW + DC 77E7E781 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingW + E0 77E7E785 17 Bytes [ EC, 53, 56, 8B, 75, 08, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingW + F3 77E7E798 26 Bytes [ FF, 75, 0C, 8B, CE, E8, 4A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingW + 10F 77E7E7B4 3 Bytes [ CA, 1F, 03 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeW + 1E 77E7E91F 126 Bytes [ 41, 41, 8A, 59, 01, 33, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeW + 9D 77E7E99E 90 Bytes [ 00, 0F, B6, CA, 83, E9, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeW + 14A 77E7EA4B 6 Bytes [ 55, 8B, EC, 56, 8B, F1 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeW + 151 77E7EA52 63 Bytes [ 46, 50, 85, C0, 0F, 85, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeW + 192 77E7EA93 32 Bytes [ FC, 89, 46, 04, 8B, 45, 10, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcParseSecurity + 5D 77E7EC1A 25 Bytes [ 8B, 75, 08, B9, 0D, F0, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcParseSecurity + 77 77E7EC34 127 Bytes [ A8, 02, 0F, 85, AA, 31, 03, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcParseSecurity + F7 77E7ECB4 23 Bytes [ 8B, 45, 10, 83, C8, 01, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcParseSecurity + 10F 77E7ECCC 37 Bytes [ 8B, 7D, 10, 6A, 05, 59, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcParseSecurity + 135 77E7ECF2 13 Bytes [ 57, FF, 15, 58, 13, E7, 77, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringBufferSize + 57 77E7EDA4 4 Bytes [ 84, 97, 64, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringBufferSize + 5C 77E7EDA9 45 Bytes [ 33, C0, AB, AB, AB, AB, AB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringBufferSize + 8A 77E7EDD7 20 Bytes [ 00, 8B, D8, 85, DB, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringBufferSize + 9F 77E7EDEC 17 Bytes [ 8B, FF, 55, 8B, EC, 6A, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMarshall + E 77E7EDFE 57 Bytes [ 1A, 03, 00, 8B, C8, 5D, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMarshall + 48 77E7EE38 7 Bytes [ 01, FF, 50, 70, 89, 46, 10 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMarshall + 50 77E7EE40 23 Bytes [ C0, 8D, 7E, 18, AB, AB, AB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMarshall + 68 77E7EE58 57 Bytes [ 00, 00, 8B, C6, 5E, 5B, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMarshall + A3 77E7EE93 56 Bytes [ 08, 8B, 11, 8B, 45, 0C, 89, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringUnmarshall + B 77E7EEDB 1 Byte [ 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringUnmarshall + D 77E7EEDD 82 Bytes [ 56, 33, F6, A8, 08, B9, 0D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringUnmarshall + 60 77E7EF30 20 Bytes [ 3D, DC, B0, EF, 77, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringUnmarshall + 84 77E7EF54 45 Bytes [ 8B, 06, 6A, 01, FF, 75, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringUnmarshall + B4 77E7EF84 49 Bytes [ 51, FF, 15, 50, 13, E7, 77, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructBufferSize + 47 77E7F150 28 Bytes [ 84, FE, 01, 03, 00, 66, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructBufferSize + 64 77E7F16D 18 Bytes [ 5D, 00, 8B, 03, 3B, C7, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMarshall + 1 77E7F180 72 Bytes [ C6, 5E, 5B, C9, C2, 08, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMarshall + 4A 77E7F1C9 25 Bytes [ FF, 55, 8B, EC, 56, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMarshall + 7E 77E7F1FD 84 Bytes [ 4D, 08, 89, 01, 74, 0F, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructUnmarshall + 1A 77E7F252 87 Bytes [ FF, 55, 8B, EC, 33, C9, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructUnmarshall + 72 77E7F2AA 59 Bytes [ EC, 8B, 45, 08, 53, 8B, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructUnmarshall + AE 77E7F2E6 43 Bytes [ 02, 00, 83, 7D, 10, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructUnmarshall + E8 77E7F320 15 Bytes [ 02, 00, 83, 7D, 18, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructUnmarshall + F8 77E7F330 33 Bytes [ 5F, 8B, C6, 5E, 5B, 5D, C2, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransGetThreadEvent + 4 77E8022B 7 Bytes [ 5E, 33, C0, 5B, C9, C2, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransGetThreadEvent + C 77E80233 4 Bytes [ 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransGetThreadEvent + 11 77E80238 34 Bytes [ 8B, FF, 55, 8B, EC, 51, 51, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransGetThreadEvent + 34 77E8025B 113 Bytes [ 43, 04, 8B, 08, 83, C0, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransGetThreadEvent + A6 77E802CD 102 Bytes [ B7, 46, 02, 50, FF, 73, 3C, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingServerFromClient + 2C 77E81C88 10 Bytes [ B7, 40, 22, 89, 86, 80, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingServerFromClient + 37 77E81C93 28 Bytes [ 95, 69, 01, 00, 8B, 86, 80, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingServerFromClient + 55 77E81CB1 5 Bytes [ 0F, 84, EE, 58, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingServerFromClient + 5B 77E81CB7 29 Bytes [ 5F, 5E, 5D, C2, 04, 00, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingServerFromClient + 79 77E81CD5 1 Byte [ 0C ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructMemorySize + C4 77E81F87 6 Bytes [ 50, 8D, 83, 58, 01, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructMemorySize + CB 77E81F8E 11 Bytes [ 50, 8D, 45, FC, 50, 53, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructMemorySize + D7 77E81F9A 35 Bytes [ 8B, F0, 85, F6, 0F, 85, F4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructMemorySize + FB 77E81FBE 32 Bytes [ 0F, 85, EE, A7, 02, 00, F6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleStructMemorySize + 11C 77E81FDF 97 Bytes [ 8B, CB, C7, 83, EC, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetCancelTimeout + 1 77E82357 30 Bytes [ 45, FC, 5F, 5E, 5B, C9, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetCancelTimeout + 20 77E82376 116 Bytes [ 46, 64, 8B, 5E, 5C, 8B, 5B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMemorySize + 43 77E823EB 85 Bytes [ 46, 60, 66, 0F, B6, 40, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMemorySize + 99 77E82441 6 Bytes [ 4E, 5C, FF, 75, E8, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMemorySize + A0 77E82448 10 Bytes [ FC, FF, 75, E4, 6A, 18, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMemorySize + AB 77E82453 15 Bytes [ 35, 00, 00, 00, 33, FF, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStringMemorySize + BB 77E82463 5 Bytes [ 00, 8B, 76, 5C, 8B ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcMapWin32Status 77E82537 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcMapWin32Status + 4 77E8253B 50 Bytes [ 41, 5C, 83, A1, 74, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcMapWin32Status + 37 77E8256E 7 Bytes [ 00, 00, 83, A6, 18, 01, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcMapWin32Status + 3F 77E82576 5 Bytes [ 00, 5E, 5D, C2, 04 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcMapWin32Status + 45 77E8257C 38 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayFree + 2 77E82C04 1 Byte [ FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayFree + 4 77E82C06 60 Bytes [ 4D, 08, 89, 01, F7, D8, 1B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayBufferSize + 27 77E82C68 25 Bytes [ 0F, 84, E1, 65, 02, 00, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayBufferSize + 41 77E82C82 15 Bytes [ 8B, 75, 08, 85, F6, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayBufferSize + 51 77E82C92 11 Bytes [ 85, C0, 0F, 84, D5, 65, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayBufferSize + 5D 77E82C9E 1 Byte [ F6 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayBufferSize + 5F 77E82CA0 3 Bytes [ 84, CA, 65 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMarshall + 26 77E82D34 25 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMarshall + 41 77E82D4F 22 Bytes [ 08, FF, 71, 60, FF, D0, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMarshall + 58 77E82D66 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMarshall + 5B 77E82D69 17 Bytes [ EC, 83, EC, 40, A1, AC, B2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMarshall + 6D 77E82D7B 239 Bytes [ 45, 0C, 57, 89, 45, C8, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayUnmarshall + 79 77E82E6B 37 Bytes [ 89, 45, 08, 47, 89, 7D, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayUnmarshall + 9F 77E82E91 132 Bytes [ 83, C7, 04, EB, D9, 80, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayUnmarshall + 124 77E82F16 79 Bytes [ 83, C1, 04, 51, 2B, C2, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayUnmarshall + 174 77E82F66 258 Bytes [ 45, 14, 01, C6, 45, 08, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMemorySize + 39 77E83069 41 Bytes [ 3D, 00, 00, 10, 00, 0F, 87, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMemorySize + 64 77E83094 52 Bytes CALL 77E830AD C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMemorySize + 99 77E830C9 75 Bytes [ 2C, 3B, C3, 0F, 85, 67, F0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMemorySize + E5 77E83115 70 Bytes [ FF, 8B, C8, 8D, 04, 39, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingArrayMemorySize + 12C 77E8315C 21 Bytes [ FF, EB, EE, 90, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMemorySize + 9 77E831A6 59 Bytes [ C2, 08, 00, 83, 7F, 0C, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMemorySize + 45 77E831E2 16 Bytes [ 84, C0, D6, FF, FF, E9, F1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMemorySize + 56 77E831F3 2 Bytes [ 9A, 87 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMemorySize + 5A 77E831F7 17 Bytes [ 8B, D0, 8B, CF, 89, 13, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructMemorySize + 6C 77E83209 80 Bytes [ CA, 83, E1, 03, F3, AA, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionBufferSize + 3B 77E832A4 140 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionBufferSize + C8 77E83331 5 Bytes [ CE, E8, D3, 5D, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionBufferSize + CE 77E83337 24 Bytes [ 85, C0, 0F, 84, 66, F9, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionBufferSize + E8 77E83351 8 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionBufferSize + F1 77E8335A 15 Bytes [ EC, 83, 3D, DC, B0, EF, 77, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMarshall + 3B 77E833B6 7 Bytes [ 85, C0, 0F, 85, E2, F8, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMarshall + 43 77E833BE 27 Bytes [ 8B, 41, 04, 83, C0, 03, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMarshall + 5F 77E833DA 16 Bytes [ 09, 00, 00, 00, 5D, C2, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMarshall + 70 77E833EB 28 Bytes [ EC, 53, 56, 8B, 75, 08, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMarshall + 8D 77E83408 7 Bytes [ 00, 00, 3B, C8, 0F, 82, 97 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionFree + 26 77E835D2 9 Bytes [ 00, 00, 0E, 00, 02, C0, B2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionFree + 30 77E835DC 1 Byte [ 0F ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionFree + 32 77E835DE 5 Bytes [ 02, C0, B3, 06, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionFree + 38 77E835E4 25 Bytes [ 10, 00, 02, C0, B4, 06, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionFree + 52 77E835FE 53 Bytes [ 02, C0, 0E, 07, 00, 00, 4A, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionUnmarshall + 30 77E836A6 28 Bytes [ 02, C0, CC, 06, 00, 00, 29, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionUnmarshall + 4D 77E836C3 50 Bytes [ 00, 2C, 00, 02, C0, D0, 06, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionUnmarshall + 80 77E836F6 25 Bytes [ 02, C0, D6, 06, 00, 00, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionUnmarshall + 9A 77E83710 26 Bytes [ D9, 06, 00, 00, 36, 00, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionUnmarshall + B6 77E8372C 49 Bytes [ 39, 00, 02, C0, DD, 06, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMemorySize + 2A 77E8384C 33 Bytes [ 4B, 00, 02, C0, 6B, 07, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMemorySize + 4C 77E8386E 53 Bytes [ 02, C0, 7C, 07, 00, 00, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMemorySize + 82 77E838A4 1 Byte [ 6F ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMemorySize + 84 77E838A6 40 Bytes [ 00, C0, 75, 07, 00, 00, 34, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonEncapsulatedUnionMemorySize + AD 77E838CF 112 Bytes [ 55, 8B, EC, 8B, 49, 6C, 5D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransServerNewConnection + 38 77E85562 8 Bytes [ 46, 4C, 2B, C3, 0F, 85, AB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransServerNewConnection + 41 77E8556B 124 Bytes [ 00, 8B, 4E, 50, 8D, 45, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransServerNewConnection + BE 77E855E8 122 Bytes [ 8B, 75, 10, 66, 83, 3E, 5C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransServerNewConnection + 139 77E85663 45 Bytes [ 8D, 7B, 04, 66, F3, A5, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransServerNewConnection + 167 77E85691 1 Byte [ 89 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructBufferSize + 78 77E85E3A 217 Bytes [ 83, 20, 00, 8B, 41, 58, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructBufferSize + 153 77E85F15 192 Bytes [ 00, 8A, 43, 02, 3C, 0C, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMarshall + 1E 77E85FD6 158 Bytes [ 0B, 85, FF, 0F, 8D, 9B, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMarshall + BD 77E86075 188 Bytes [ 4F, 58, 83, C0, 04, 50, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMarshall + 17A 77E86132 27 Bytes [ 00, 0F, 84, 9C, F9, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMarshall + 196 77E8614E 44 Bytes [ FF, 8B, 06, 8B, CE, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMarshall + 1C3 77E8617B 3 Bytes [ 00, 00, 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMemorySize + 50 77E86321 11 Bytes [ 33, FF, EB, F4, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMemorySize + 72 77E86343 24 Bytes [ 80, 84, 00, 00, 00, 85, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMemorySize + 8B 77E8635C 27 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMemorySize + A7 77E86378 27 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructMemorySize + C4 77E86395 111 Bytes [ 85, 7E, 4D, 02, 00, 8B, 4D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructUnmarshall + 1 77E8644A 100 Bytes [ 4D, 0C, 83, 60, 10, 00, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructUnmarshall + 66 77E864AF 5 Bytes [ 55, 8B, EC, 53, 56 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructUnmarshall + 6C 77E864B5 52 Bytes [ 75, 08, 57, 8B, 7E, 5C, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructUnmarshall + A1 77E864EA 7 Bytes [ 00, C7, 41, 08, 03, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructUnmarshall + A9 77E864F2 56 Bytes [ 89, 59, 0C, 89, 59, 4C, 89, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeUnmarshall + 43 77E86691 29 Bytes [ 8B, 45, 0C, FF, 70, 38, 68, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrSimpleTypeUnmarshall + 62 77E866B0 80 Bytes [ 3B, C3, 89, 86, 94, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructFree + 3E 77E86701 46 Bytes [ C7, 06, 30, 80, E7, 77, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructFree + 6D 77E86730 7 Bytes [ 00, C7, 46, 08, 40, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructFree + 75 77E86738 41 Bytes [ 89, 9E, F4, 00, 00, 00, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructFree + 9F 77E86762 20 Bytes [ 89, 5E, 0C, 39, 1D, FC, B0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexStructFree + B4 77E86777 8 Bytes [ 5F, 8B, C6, 5E, 5B, 5D, C2, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingIsClientLocal + 14 77E86A53 58 Bytes [ 5D, 10, 56, 57, 8B, 3B, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingIsClientLocal + 4F 77E86A8E 117 Bytes [ 00, 0F, 87, A3, 0B, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingIsClientLocal + C6 77E86B05 4 Bytes [ 10, 83, E8, 2C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingIsClientLocal + CB 77E86B0A 85 Bytes CALL 9C5CAB99
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingIsClientLocal + 122 77E86B61 72 Bytes [ 0F, B6, 46, 02, FF, 45, 0C, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionFreePacket + 10 77E88384 33 Bytes JMP 77E8843F C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcLogEvent + 31 77E883BB 116 Bytes [ FF, 75, 20, FF, 75, 1C, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcLogEvent + A6 77E88430 10 Bytes [ 75, 14, 50, 83, 7D, FC, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcLogEvent + CA 77E88454 61 Bytes [ 00, 00, FF, 75, 14, E8, C8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcLogEvent + 137 77E884C1 78 Bytes CALL 605CDB3D
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcLogEvent + 186 77E88510 78 Bytes CALL 94AB4E8C
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayFree + 5 77E88E13 37 Bytes [ 56, 8B, 75, 08, 57, 8D, 7E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayFree + 2B 77E88E39 57 Bytes [ 57, FF, 15, 58, 13, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayFree + 65 77E88E73 231 Bytes [ 55, 8B, EC, 6A, 00, 6A, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayFree + 14D 77E88F5B 45 Bytes [ 77, 90, 90, 90, 90, 90, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayFree + 17B 77E88F89 1 Byte [ F1 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMarshall + 10 77E89667 40 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMarshall + 3A 77E89691 103 Bytes [ 85, C0, 0F, 85, D0, 1D, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMarshall + A2 77E896F9 42 Bytes [ 37, FF, 15, F8, 10, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMarshall + CD 77E89724 3 Bytes [ FF, C3, 52 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMarshall + D1 77E89728 2 Bytes [ 1B, 07 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayBufferSize + 61 77E89807 52 Bytes [ 30, 8B, 0D, A0, B0, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayUnmarshall + 2D 77E8983D 5 Bytes [ 00, 83, A6, 8C, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayUnmarshall + 35 77E89845 145 Bytes [ 6A, 00, 68, BF, 06, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayUnmarshall + C7 77E898D7 2 Bytes [ A6, D8 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayUnmarshall + CA 77E898DA 29 Bytes [ 00, 00, 00, 5F, 5E, C3, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMemorySize + 4 77E898F8 46 Bytes [ 31, 83, 3C, 86, 00, 75, 1B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMemorySize + 33 77E89927 90 Bytes [ 24, 8E, 00, FF, 02, EB, DB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMemorySize + D4 77E899C8 29 Bytes [ 8D, BE, 90, 00, 00, 00, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMemorySize + F2 77E899E6 92 Bytes [ 2C, 8D, 45, FC, 8B, CB, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrComplexArrayMemorySize + 14F 77E89A43 309 Bytes [ 83, F2, FF, FF, 8D, 8E, 90, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateStubFromTypeInfo 77E89CB5 112 Bytes [ 90, 90, 90, 90, 8B, FF, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateStubFromTypeInfo + 71 77E89D26 15 Bytes CALL 77E898E3 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateStubFromTypeInfo + 81 77E89D36 38 Bytes [ 5D, FC, 8D, 7E, 4C, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateStubFromTypeInfo + A8 77E89D5D 69 Bytes [ 00, 3B, CB, 74, 07, 8B, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateStubFromTypeInfo + 11D 77E89DD2 5 Bytes [ 00, FF, 36, 89, 39 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqObject + 17 77E8A15B 56 Bytes [ BB, 49, 01, 00, 8B, 45, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqObject + 50 77E8A194 27 Bytes [ 03, C1, 3B, 45, F8, 0F, 87, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqObject + 6C 77E8A1B0 68 Bytes [ 0F, 84, C5, 77, 02, 00, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqLocalClientPID + 2A 77E8A1F5 78 Bytes [ 75, 0C, 89, 45, F8, 8B, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqLocalClientPID + 79 77E8A244 1 Byte [ 75 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqLocalClientPID + 7B 77E8A246 78 Bytes [ 56, FF, 55, F8, 01, 5D, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqLocalClientPID + CA 77E8A295 10 Bytes [ 00, 8B, 51, 10, 89, 50, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqLocalClientPID + D5 77E8A2A0 21 Bytes [ 00, 00, 83, 60, 08, 00, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetObject + E 77E8A414 113 Bytes [ 02, 00, 46, 46, 0F, BF, 06, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetObject + 80 77E8A486 7 Bytes [ A8, 18, 75, 07, 83, A3, 88 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetObject + 89 77E8A48F 90 Bytes [ 00, 00, 8B, 45, 10, 89, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetObject + E4 77E8A4EA 17 Bytes [ 00, 00, 57, C6, 45, FF, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetObject + F6 77E8A4FC 13 Bytes [ FF, 8B, 7D, 0C, 8A, 4F, 01, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExW + 8A 77E8A5A8 53 Bytes [ 01, 00, 3C, 2F, 0F, 84, 5B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientW + 22 77E8A5DE 51 Bytes [ 33, C0, 8A, 07, 50, E8, C4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientW + 56 77E8A612 157 Bytes [ FF, A8, 18, 0F, 85, 71, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSend + 1B 77E8A6B1 50 Bytes [ 89, 46, 30, 8B, 46, 14, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSend + 4E 77E8A6E4 63 Bytes [ 45, F4, 89, 46, 40, 8B, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncSetHandle + 29 77E8A724 53 Bytes CALL 77E89F51 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncSetHandle + 5F 77E8A75A 31 Bytes [ 75, 0C, 89, 45, FC, 8B, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncSetHandle + 7F 77E8A77A 13 Bytes [ 0F, 84, DC, 72, 02, 00, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncSetHandle + 8E 77E8A789 51 Bytes [ 34, 8B, 45, FC, 89, 46, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncSetHandle + C2 77E8A7BD 5 Bytes [ 39, BE, 88, 00, 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReceive + 42 77E8ADA3 6 Bytes [ A8, 10, 0F, 84, A3, 70 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReceive + 94 77E8ADF5 63 Bytes [ F8, 85, FF, 0F, 84, 1E, 62, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReceive + D4 77E8AE35 10 Bytes [ 83, D8, FF, 5D, C2, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReceive + DF 77E8AE40 2 Bytes [ 48, 04 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReceive + E2 77E8AE43 53 Bytes [ 55, 0C, 83, C1, 07, 83, E1, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheAllocate + 13 77E8B59C 119 Bytes [ 45, 14, 85, C0, 0F, 85, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheAllocate + 8B 77E8B614 4 Bytes [ 84, 87, 16, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheAllocate + 90 77E8B619 54 Bytes [ 49, 0F, 84, 98, 8D, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheAllocate + C7 77E8B650 7 Bytes [ 00, 8B, 07, 8B, 4D, 14, 89 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBCacheAllocate + D9 77E8B662 26 Bytes [ 32, 03, 45, EC, 50, 53, E8, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateProxyFromTypeInfo + D 77E8BBAE 26 Bytes [ D0, 01, 86, 9C, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateProxyFromTypeInfo + 28 77E8BBC9 1 Byte [ C0 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateProxyFromTypeInfo + 2A 77E8BBCB 4 Bytes [ 85, 24, 20, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateProxyFromTypeInfo + 2F 77E8BBD0 131 Bytes [ 39, 5E, 14, 0F, 84, 43, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!CreateProxyFromTypeInfo + B3 77E8BC54 56 Bytes [ 5D, 08, 85, DB, 75, 1F, 8D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetOption + C 77E8BDC5 5 Bytes [ 00, FF, B6, AC, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetOption + 12 77E8BDCB 42 Bytes CALL 77E88772 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetOption + 3D 77E8BDF6 29 Bytes [ 55, 8B, EC, 8B, 41, 14, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetOption + 5C 77E8BE15 2 Bytes [ 5B, 3A ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetOption + 60 77E8BE19 133 Bytes [ 4A, 0F, 84, 3D, 3A, 02, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalFree + 5 77E8C0D3 18 Bytes [ BC, 01, 00, 00, A1, AC, B2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalFree + 18 77E8C0E6 13 Bytes [ F1, 33, FF, 39, BE, D8, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalFree + 27 77E8C0F5 19 Bytes [ 0F, 84, 9F, 1B, 00, 00, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalFree + 3C 77E8C10A 1 Byte [ 04 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalFree + 3F 77E8C10D 13 Bytes [ 87, E4, 00, 00, 00, 56, 50, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetUserMarshalInfo + 1D 77E8C13F 37 Bytes [ CF, FF, 50, 68, 83, 78, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetUserMarshalInfo + 43 77E8C165 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetUserMarshalInfo + 46 77E8C168 14 Bytes [ EC, 51, 51, 53, 56, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetUserMarshalInfo + 55 77E8C177 124 Bytes [ 01, 8D, 55, FC, 52, 6A, 09, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalBufferSize + B 77E8C1F4 91 Bytes [ 83, 90, 00, 00, 00, 8B, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalBufferSize + 67 77E8C250 33 Bytes [ 00, 56, FF, 15, 5C, 13, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalBufferSize + 89 77E8C272 60 Bytes [ 15, 58, 13, E7, 77, 8B, C7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalBufferSize + C6 77E8C2AF 6 Bytes [ F1, 33, C0, 39, 46, 08 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalBufferSize + CD 77E8C2B6 77 Bytes [ 84, 5D, D0, 01, 00, 8B, 4D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMarshall + 34 77E8C304 56 Bytes [ 00, 00, F6, 45, F8, 01, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMarshall + 6E 77E8C33E 8 Bytes [ 0F, 85, E0, 20, 02, 00, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMarshall + 77 77E8C347 35 Bytes [ 01, 00, 00, 0F, 87, DE, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMarshall + 9B 77E8C36B 11 Bytes [ 93, AC, 00, 00, 00, 89, 51, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMarshall + A7 77E8C377 18 Bytes [ 00, 00, 8B, 8B, 90, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalUnmarshall + 46 77E8C428 2 Bytes [ 54, 20 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalUnmarshall + 4A 77E8C42C 82 Bytes [ 8B, 83, 90, 00, 00, 00, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalUnmarshall + 9D 77E8C47F 66 Bytes [ FF, FF, FF, FF, FF, 06, 67, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalUnmarshall + E1 77E8C4C3 27 Bytes [ 33, DB, 39, 5D, 14, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalUnmarshall + FD 77E8C4DF 29 Bytes [ 86, 84, 00, 00, 00, 85, C0, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantArrayMemorySize + 41 77E8DECC 428 Bytes CALL 77E887F7 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRangeUnmarshall + DB 77E8E079 43 Bytes [ 81, 8B, 08, 8D, 71, 14, 6A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRangeUnmarshall + 107 77E8E0A5 62 Bytes [ 45, 1C, 89, 45, F4, 7C, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRangeUnmarshall + 147 77E8E0E5 34 Bytes [ 43, CC, 00, 00, 39, 75, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRangeUnmarshall + 16A 77E8E108 9 Bytes [ 8C, 42, F6, 01, 00, 83, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRangeUnmarshall + 174 77E8E112 23 Bytes [ 4D, 20, 0F, 8F, 41, F6, 01, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExW + 40 77E8E5DE 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExW + 42 77E8E5E0 23 Bytes [ 39, 3B, 75, 18, 3B, C7, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExW + 5A 77E8E5F8 24 Bytes [ 01, 00, 00, 00, 5F, 8B, C6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExW + 73 77E8E611 15 Bytes [ 8B, EC, 81, EC, F4, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExW + 84 77E8E622 1 Byte [ FC ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf2 + C 77E901FE 5 Bytes [ 6F, 00, 77, 00, 73 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf2 + 12 77E90204 59 Bytes [ 20, 00, 4E, 00, 54, 00, 5C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf2 + 4E 77E90240 21 Bytes [ 45, 00, 78, 00, 65, 00, 63, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf2 + 64 77E90256 25 Bytes [ 70, 00, 74, 00, 69, 00, 6F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf2 + 7E 77E90270 25 Bytes [ 77, 00, 61, 00, 72, 00, 65, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcRequestMutex + 16 77E9065B 72 Bytes [ 35, BC, B4, EF, 77, 89, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcClearMutex + 36 77E906A4 57 Bytes [ 29, 75, F4, 89, 7D, FC, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcClearMutex + 70 77E906DE 82 Bytes [ C1, E0, 04, 89, 01, 33, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcClearMutex + C3 77E90731 12 Bytes [ B3, B3, 00, 00, 53, 56, BB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcClearMutex + D0 77E9073E 185 Bytes [ 15, 5C, 13, E7, 77, 39, 3D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcClearMutex + 18A 77E907F8 2 Bytes [ 47, 89 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpW + 2 77E90A37 39 Bytes [ 8B, F0, 85, F6, 59, 74, 16, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpW + 5A 77E90A8F 174 Bytes [ 55, 8B, EC, 56, 57, 6A, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpW + 10B 77E90B40 71 Bytes [ 3B, C6, A3, BC, B0, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpW + 154 77E90B89 189 Bytes [ 3B, C6, A3, B8, B0, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpW + 212 77E90C47 56 Bytes [ 89, BE, 88, 00, 00, 00, 89, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIfEx + 20 77E90D33 59 Bytes CALL 77E90D5D C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIfEx + 5C 77E90D6F 205 Bytes [ 8B, 7D, 08, 89, 76, 04, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIfEx + 12B 77E90E3E 56 Bytes [ 3B, C3, 59, 89, 46, 2C, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIfEx + 165 77E90E78 1 Byte [ F0 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIfEx + 167 77E90E7A 35 Bytes [ 6A, 04, 6A, 02, 57, 8B, 3D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayFree + 2 77E90EBB 38 Bytes [ FF, 85, C0, 0F, 85, E6, E9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayFree + 29 77E90EE2 77 Bytes [ 8B, FF, 55, 8B, EC, 51, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayUnmarshall + 10 77E90F5F 20 Bytes [ EC, 56, FF, 75, 08, 8B, F1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayUnmarshall + 25 77E90F74 43 Bytes [ 33, C9, C7, 46, 40, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayUnmarshall + 51 77E90FA0 11 Bytes [ 00, 0A, 00, 00, 00, 8B, C6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayUnmarshall + 5D 77E90FAC 9 Bytes [ 90, 90, 90, 90, 90, 6A, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayUnmarshall + 67 77E90FB6 112 Bytes JMP F81BF832
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionReallocPacket + 62 77E91689 51 Bytes [ 00, 00, 80, FF, 75, 08, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionReallocPacket + 96 77E916BD 41 Bytes [ 55, 8B, EC, 83, EC, 14, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionReallocPacket + C0 77E916E7 81 Bytes [ 57, 8B, 7D, 0C, 68, 90, E6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionReallocPacket + 112 77E91739 4 Bytes [ 75, 14, 8B, C8 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransConnectionReallocPacket + 117 77E9173E 8 Bytes [ 75, 0C, FF, 75, 08, E8, 38, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesHandleFree + D 77E91B21 5 Bytes [ 0C, 89, 85, 74, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesHandleFree + 13 77E91B27 13 Bytes [ FF, 8B, 06, 85, C0, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesHandleFree + 21 77E91B35 123 Bytes [ FF, C7, 85, 78, FF, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesHandleFree + 9F 77E91BB3 51 Bytes CALL 77E91BD8 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesHandleFree + D3 77E91BE7 6 Bytes [ 4D, F4, E8, 81, 91, FE ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesBufferHandleReset + 17 77E91C73 5 Bytes [ 13, E7, 77, 33, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesBufferHandleReset + 1D 77E91C79 6 Bytes [ 8D, 45, EC, 89, 45, DC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesBufferHandleReset + 24 77E91C80 80 Bytes [ 45, 0C, 68, 00, 01, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesBufferHandleReset + 75 77E91CD1 51 Bytes [ 00, 00, 5F, 5E, 5B, C9, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesBufferHandleReset + AA 77E91D06 110 Bytes [ 00, 33, C0, 5E, 5D, C2, 04, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesEncodeFixedBufferHandleCreate + 1A 77E91E4E 15 Bytes [ 46, 46, 0F, BF, 06, 03, F0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesEncodeFixedBufferHandleCreate + 6B 77E91E9F 70 Bytes JMP 77EAA542 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesEncodeFixedBufferHandleCreate + B2 77E91EE6 163 Bytes [ 8B, FF, 55, 8B, EC, 8B, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode2 + 4A 77E91F8A 9 Bytes [ 0C, 89, 4D, 10, 0F, 87, BE, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode2 + 54 77E91F94 27 Bytes [ 3B, C3, 0F, 82, B6, 02, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode2 + 70 77E91FB0 5 Bytes [ 0F, 84, 24, 3C, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode2 + 76 77E91FB6 34 Bytes [ 8B, 47, 68, 85, C0, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize2 + A 77E91FD9 37 Bytes [ F3, F3, A5, 8B, C8, 83, E1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize2 + 31 77E92000 11 Bytes CALL E56D2F20
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize2 + 3D 77E9200C 23 Bytes [ 48, 0F, 84, 70, F9, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize + 9 77E92024 7 Bytes [ 0C, 56, FF, D0, E9, AA, 4E ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize + 11 77E9202C 62 Bytes [ FF, 0F, BF, D0, 03, D3, 84, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize + 50 77E9206B 35 Bytes [ C7, 45, F0, 01, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize + 74 77E9208F 13 Bytes CALL EB6D2FAF
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeAlignSize + 82 77E9209D 44 Bytes CALL C16E2FA7
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode + 2D 77E92101 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode + 33 77E92107 160 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode + D4 77E921A8 26 Bytes [ C1, E0, 02, 01, 46, 04, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode + EF 77E921C3 17 Bytes JMP 77E87518 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeEncode + 101 77E921D5 7 Bytes [ 08, 0F, 85, 1A, 54, FF, FF ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesDecodeBufferHandleCreate + 5E 77E922B9 54 Bytes [ 3A, 51, 56, 89, 7E, 3C, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode + 3C 77E92310 4 Bytes CALL 77EA1756 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode + 41 77E92315 45 Bytes [ 00, 83, F8, 01, 75, D1, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode + 6F 77E92343 40 Bytes [ 00, 8D, 45, F4, 50, 6A, 38, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode + 98 77E9236C 44 Bytes [ 45, F8, 50, 8D, BE, BC, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode + C5 77E92399 14 Bytes [ 4E, 64, 8B, 40, 08, 89, 46, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode2 + 56 77E92426 5 Bytes [ 0F, 84, AC, 4F, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode2 + 5C 77E9242C 42 Bytes [ 33, F6, 53, FF, 15, 58, 13, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode2 + 88 77E92458 18 Bytes [ 00, 8B, 11, 89, 50, 04, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode2 + 9B 77E9246B 63 Bytes CALL 77E9247D C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeDecode2 + DB 77E924AB 7 Bytes [ 56, 8B, CF, E8, 1B, FE, FF ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetServerStackSize + 3F 77E92906 97 Bytes [ 50, 08, 89, 45, 08, 8D, 47, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetServerStackSize + A1 77E92968 11 Bytes [ 00, 00, 0F, 88, D9, 60, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetServerStackSize + AD 77E92974 3 Bytes [ C0, 18, 50 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetServerStackSize + B2 77E92979 1 Byte [ 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetServerStackSize + B4 77E9297B 26 Bytes CALL 77E8123C C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerFree 77E92AE7 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerFree + 4 77E92AEB 168 Bytes [ FF, 55, 8B, EC, 8B, 45, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerUnmarshall + 3F 77E92B94 78 Bytes [ 00, 01, 75, 0C, 83, 4D, FC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerUnmarshall + 8E 77E92BE3 116 Bytes [ 75, 21, 8B, 89, E4, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerUnmarshall + 10C 77E92C61 18 Bytes [ 56, 8B, 75, 08, 56, E8, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerUnmarshall + 120 77E92C75 8 Bytes [ 3B, F1, 53, 57, 0F, 84, 63, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrByteCountPointerUnmarshall + 129 77E92C7E 98 Bytes [ 00, 8B, 7D, 14, 3B, F9, 0F, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryPointer + 7 77E93227 46 Bytes [ 46, 04, 80, 38, 01, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryPointer + 36 77E93256 6 Bytes [ 90, 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryPointer + 3D 77E9325D 38 Bytes [ 55, 8B, EC, 83, 7D, 08, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryPointer + 65 77E93285 2 Bytes [ 75, 3B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryPointer + 68 77E93288 196 Bytes [ 06, C6, 80, E5, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatInit + 6E 77E9334D 263 Bytes [ 46, 4C, 33, C0, 8A, 07, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatInit + 178 77E93457 37 Bytes JMP 77E934D3 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatInit + 19E 77E9347D 23 Bytes [ 00, FE, 7F, 8B, 02, F7, 62, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatInit + 1B6 77E93495 43 Bytes [ 89, 98, 00, 00, 00, E8, 12, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerXlatInit + 1E2 77E934C1 9 Bytes [ 53, 56, 8B, 75, 08, 81, C6, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerConstruct + 4 77E93A4C 18 Bytes [ 45, FC, 53, FF, 75, 24, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerConstruct + 17 77E93A5F 15 Bytes [ 70, 0C, FF, 70, 04, 8B, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerConstruct + 27 77E93A6F 48 Bytes CALL 77E94404 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerConstruct + 58 77E93AA0 22 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerConstruct + 6F 77E93AB7 3 Bytes [ 8B, 4D, 08 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetComTimeout + 40 77E93C5C 17 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetComTimeout + 53 77E93C6F 146 Bytes CALL 77E93D00 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetComTimeout + E6 77E93D02 38 Bytes [ 8B, FF, 55, 8B, EC, 51, 53, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetComTimeout + 10D 77E93D29 10 Bytes [ 83, 7D, 0C, 04, 0F, 84, BC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerCheckClientRestriction + 6 77E93D34 21 Bytes [ 7D, 0C, 06, 0F, 84, 3E, B2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerCheckClientRestriction + 1C 77E93D4A 29 Bytes [ 45, 14, 89, 10, A1, D8, B1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerCheckClientRestriction + 88 77E93DB6 45 Bytes [ 5F, 5E, C3, 90, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerCheckClientRestriction + B6 77E93DE4 69 Bytes [ FF, 8B, F8, 85, FF, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerExplode + 1F 77E93E2A 2 Bytes [ 84, 18 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerExplode + 25 77E93E30 14 Bytes [ 4D, FC, 51, 8B, C8, E8, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerExplode + 34 77E93E3F 4 Bytes [ 84, 26, B4, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerExplode + 39 77E93E44 4 Bytes [ 83, 7D, FC, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!TowerExplode + 3E 77E93E49 4 Bytes [ 85, 24, B4, 01 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryRefId + A 77E94061 4 Bytes [ 88, 78, 01, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryRefId + F 77E94066 41 Bytes [ 75, C8, 83, 6D, C0, 18, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerQueryRefId + 39 77E94090 109 Bytes [ 9A, 78, 01, 00, FF, 75, D8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerFree + 29 77E940FE 68 Bytes [ 56, 8B, CB, FF, 50, 28, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerFree + 6E 77E94143 3 Bytes [ 61, FD, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerFree + 72 77E94147 6 Bytes [ 33, F6, E9, EE, FC, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerInsertRefId + 2 77E9414E 95 Bytes [ BE, D3, 06, 00, 00, E9, 3B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerInsertRefId + 89 77E941D5 10 Bytes JMP 77E8E4BB C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerInsertRefId + 95 77E941E1 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerInsertRefId + 99 77E941E5 2 Bytes [ EC, 56 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFullPointerInsertRefId + 9C 77E941E8 2 Bytes [ 75, 08 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoW + 30 77E94490 16 Bytes [ 59, 8B, D8, 43, 8B, C3, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoW + 41 77E944A1 22 Bytes CALL 05B1AA2F
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoW + 58 77E944B8 19 Bytes [ D8, 3B, DF, 0F, 85, 16, 68, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoW + 6C 77E944CC 16 Bytes [ 8B, D8, 3B, DF, 0F, 85, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoW + 7D 77E944DD 128 Bytes [ 75, 28, FF, 75, 24, FF, 75, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqBindings + 24 77E945C1 26 Bytes [ 8B, 0E, 8B, 56, 0C, 89, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqBindings + 3F 77E945DC 7 Bytes [ 45, D8, 3B, 45, E0, 72, 94 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqBindings + 47 77E945E4 118 Bytes [ DB, 39, 7D, E0, 76, 0F, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqBindings + BE 77E9465B 2 Bytes [ 6F, 2C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqBindings + C2 77E9465F 22 Bytes [ 59, 66, 83, 7D, A4, FF, 74, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingVectorFree + 13 77E94745 3 Bytes [ 49, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingVectorFree + 17 77E94749 19 Bytes [ 00, 02, 00, 28, 00, 32, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingVectorFree + 2B 77E9475D 32 Bytes [ 00, 00, 00, 48, 00, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingVectorFree + 4C 77E9477E 9 Bytes [ 48, 00, 18, 00, 08, 00, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingVectorFree + 56 77E94788 19 Bytes [ 08, 00, 13, 00, 20, 00, 78, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMapCommAndFaultStatus + 3B 77E948A4 9 Bytes [ 00, 00, 08, 00, 00, 00, C8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMapCommAndFaultStatus + 45 77E948AE 13 Bytes [ 04, 00, 0E, 00, 50, 21, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMapCommAndFaultStatus + 53 77E948BC 5 Bytes [ 06, 00, 70, 00, 10 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMapCommAndFaultStatus + 59 77E948C2 25 Bytes [ 10, 00, 00, 49, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMapCommAndFaultStatus + 73 77E948DC 53 Bytes [ 02, 00, 00, 00, 18, 01, 04, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcIfInqId + C 77E94946 16 Bytes [ 08, 00, 00, 00, 40, 01, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcIfInqId + 1D 77E94957 29 Bytes [ 00, 08, 00, 00, 48, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcIfInqId + 3B 77E94975 6 Bytes [ 00, 00, 00, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcIfInqId + 43 77E9497D 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcIfInqTransferSyntaxes + 1 77E94981 20 Bytes [ EC, 8B, 45, 0C, 56, 8B, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcIfInqTransferSyntaxes + 16 77E94996 40 Bytes [ 00, 33, FF, 85, FF, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcIfInqTransferSyntaxes + 3F 77E949BF 16 Bytes [ 85, FF, 66, C7, 00, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointW + C 77E949D0 5 Bytes [ 66, C7, 40, 03, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointW + 12 77E949D6 24 Bytes [ C6, 40, 05, 00, 33, C0, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointW + 2B 77E949EF 73 Bytes [ 85, C0, 0F, 84, 83, 76, FE, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingA + 31 77E94A39 30 Bytes JMP 12B025FF
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingA + 50 77E94A58 38 Bytes CALL 77E94A3B C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingA + 77 77E94A7F 34 Bytes [ FF, 85, C0, 75, 7A, 8B, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingA + 9A 77E94AA2 31 Bytes [ 75, 08, 89, 30, 66, 8B, 4D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingToStringBindingA + BA 77E94AC2 26 Bytes [ 00, 66, C7, 47, 19, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringBufferSize + 16 77E94ADD 249 Bytes [ 8B, 75, F8, 8B, C1, C1, E9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringMemorySize + 26 77E94BD7 29 Bytes [ 83, 7D, 10, 00, 74, 09, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringMemorySize + 44 77E94BF5 3 Bytes [ 85, 20, 60 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringMemorySize + 49 77E94BFA 18 Bytes [ FF, 75, 18, FF, 36, E8, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringMemorySize + 5C 77E94C0D 18 Bytes [ 8D, 65, EC, 5F, 5E, 5B, C9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringMemorySize + 6F 77E94C20 77 Bytes [ EC, 83, 3D, DC, B0, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringUnmarshall + 22 77E94C6E 8 Bytes [ 89, 41, 20, 33, C0, 5D, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringUnmarshall + 2C 77E94C78 94 Bytes [ 7D, 0C, AB, AB, AB, AB, AB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringUnmarshall + 8B 77E94CD7 69 Bytes [ 90, 6E, 63, 61, 63, 6E, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNonConformantStringUnmarshall + D1 77E94D1D 44 Bytes [ 90, 90, 90, 6E, 63, 61, 63, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterA + DB 77E94E21 69 Bytes [ 7C, 01, 04, 8D, 48, 06, 3B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterA + 121 77E94E67 70 Bytes [ F6, 0F, 84, 53, 03, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterA + 169 77E94EAF 34 Bytes [ 1C, 0F, B7, 45, 08, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterA + 18C 77E94ED2 193 Bytes [ 55, 8B, EC, 8B, 45, 08, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterA + 24E 77E94F94 33 Bytes [ E7, 82, 01, 00, 56, 8B, 75, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseA + DA 77E95312 12 Bytes [ F3, FF, FF, 8B, 45, 20, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseA + E7 77E9531F 38 Bytes JMP 77E94433 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseA + 10E 77E95346 49 Bytes [ 76, 12, FF, 0E, 8B, 06, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseA + 140 77E95378 21 Bytes [ EC, 56, FF, 75, 14, 8B, F1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingParseA + 157 77E9538F 9 Bytes [ 75, 0A, 83, 7D, 0C, 09, 0F, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingToStaticStringBindingW + 3F 77E95547 3 Bytes [ 44, 24, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingToStaticStringBindingW + 43 77E9554B 22 Bytes [ FF, 35, E0, B1, EF, 77, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingToStaticStringBindingW + 5A 77E95562 5 Bytes [ 15, 58, 13, E7, 77 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingToStaticStringBindingW + 60 77E95568 1 Byte [ 45 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingToStaticStringBindingW + 62 77E9556A 50 Bytes [ 8B, 4D, F8, 89, 08, 33, C0, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2W + 23 77E956BC 203 Bytes [ 8C, D1, E4, 01, 00, 33, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2W + EF 77E95788 35 Bytes [ 85, C0, 74, B9, EB, F6, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2W + 113 77E957AC 4 Bytes [ 8B, 45, 20, C7 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2W + 118 77E957B1 29 Bytes JMP 77E9116F C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2W + 136 77E957CF 37 Bytes [ 8B, 45, 0C, 66, 89, 10, E9, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoA + 9D 77E95DCF 44 Bytes CALL 77E95DE8 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoA + CA 77E95DFC 143 Bytes [ 75, 0C, 39, 3E, 0F, 84, AB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoA + 15A 77E95E8C 53 Bytes [ 89, 4D, D4, 89, 4D, E0, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoA + 190 77E95EC2 112 Bytes [ C8, 85, C0, 74, 13, FF, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterAuthInfoA + 201 77E95F33 39 Bytes [ 75, DC, FF, 75, E0, 68, 8C, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqDefaultPrincNameW + 57 77E960E3 1 Byte [ 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqDefaultPrincNameW + 59 77E960E5 2 Bytes [ 89, 7B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqDefaultPrincNameW + 5C 77E960E8 57 Bytes [ EB, B5, C6, 83, 94, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqDefaultPrincNameW + 96 77E96122 2 Bytes [ 45, B8 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqDefaultPrincNameW + 99 77E96125 15 Bytes [ 30, 8D, 45, D4, 50, 57, 89, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterW + 32 77E96828 191 Bytes [ FE, FF, FF, 43, 83, C6, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExW + 49 77E968EF 1 Byte [ 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExW + 4B 77E968F1 20 Bytes [ EC, 83, EC, 2C, 56, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExW + 60 77E96906 37 Bytes [ 84, 00, E5, 01, 00, 8B, 4D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExW + 86 77E9692C 54 Bytes [ 85, F6, 8B, 45, 14, 57, 6A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExW + BD 77E96963 36 Bytes [ 0F, 84, 1B, 01, 00, 00, 3B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreateSequential + 3E 77E98809 143 Bytes [ 0F, 84, DE, AA, FE, FF, E9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreateSequential + CE 77E98899 29 Bytes [ 00, 00, 90, 81, C2, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreateSequential + EC 77E988B7 4 Bytes [ 8B, 87, 28, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreateSequential + F1 77E988BC 20 Bytes [ 00, 89, 43, 04, 8D, 45, A4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCreateSequential + 106 77E988D1 46 Bytes [ 45, 10, 89, 45, A8, 0F, 84, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseqEp2A + 18 77E99560 33 Bytes [ 85, C0, 74, CA, EB, D5, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseqEp2A + 3A 77E99582 99 Bytes [ 15, 04, 12, E7, 77, 8B, 4E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseqEp2A + 9E 77E995E6 23 Bytes [ 00, 81, FB, 11, 03, 09, 80, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseqEp2A + B6 77E995FE 5 Bytes [ 00, 85, DB, 75, 1D ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidToStringW + 1 77E99604 50 Bytes [ 46, 40, A8, 04, 74, 05, F6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidToStringW + 34 77E99637 41 Bytes [ 85, DB, 0F, 85, B8, 57, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidToStringW + 5E 77E99661 119 Bytes [ 00, 85, C0, 0F, 85, 54, 58, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpA + 59 77E996D9 22 Bytes [ C0, 57, 8D, 45, F8, 50, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqEpA + 70 77E996F0 104 Bytes [ 45, 08, 0F, 84, 1B, 6F, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfW + 2A 77E99759 35 Bytes [ 5F, 5E, 5B, C9, C2, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExW + 1A 77E9977E 57 Bytes [ 3B, C6, 0F, 85, 02, E3, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExW + 54 77E997B8 5 Bytes [ 8D, 44, 0F, 08, 89 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExW + 5A 77E997BE 21 Bytes JMP 77E85D19 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExW + 70 77E997D4 43 Bytes [ 39, 3D, DC, B0, EF, 77, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExW + 9C 77E99800 15 Bytes [ D6, A3, A0, B5, EF, 77, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEnableIdleCleanup + 1D 77E99D00 19 Bytes CALL 77E99569 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEnableIdleCleanup + 31 77E99D14 5 Bytes [ 50, 28, FF, 76, 1C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEnableIdleCleanup + 37 77E99D1A 71 Bytes [ 86, 80, 00, 00, 00, FF, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtIsServerListening + 1B 77E99D62 5 Bytes [ 00, E9, 5C, 2F, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtIsServerListening + 21 77E99D68 10 Bytes [ 33, C0, 39, 46, 14, 0F, 84, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtIsServerListening + 2C 77E99D73 117 Bytes JMP 77EACCED C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIf + C 77E99DE9 8 Bytes [ 00, 8B, C8, 57, E8, 6A, BA, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIf + 15 77E99DF2 8 Bytes [ 85, C0, 89, 43, 64, 0F, 84, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIf + 1E 77E99DFB 14 Bytes [ 00, 00, 83, 7D, E4, 00, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIfEx + 18 77E99E27 112 Bytes CALL 77E9922B C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIfEx + 89 77E99E98 23 Bytes JMP 77E86A3A C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIfEx + A1 77E99EB0 84 Bytes [ 85, C0, 0F, 85, 4C, 50, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIfEx + F6 77E99F05 10 Bytes [ 00, 00, 00, 44, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsIfEx + 101 77E99F10 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerSetAddressChangeFn + 4 77E9A815 9 Bytes [ 45, 08, 6B, C0, 0E, 56, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerSetAddressChangeFn + E 77E9A81F 120 Bytes JMP 8467E19B
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSystemFunction001 + 6F 77E9A898 10 Bytes [ 01, 00, 06, 00, 10, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSystemFunction001 + 7A 77E9A8A3 36 Bytes [ 00, 06, 00, 01, 00, E9, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSystemFunction001 + A0 77E9A8C9 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSystemFunction001 + A9 77E9A8D2 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSystemFunction001 + B2 77E9A8DB 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerRegisterForwardFunction + C 77E9A8F7 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerRegisterForwardFunction + 12 77E9A8FD 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerRegisterForwardFunction + 1F 77E9A90A 30 Bytes [ 06, 00, 10, 00, 00, 01, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerRegisterForwardFunction + 3F 77E9A92A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerRegisterForwardFunction + 43 77E9A92E 24 Bytes [ 00, 00, 18, 00, 02, 00, 02, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqAddressChangeFn + 11 77E9AE4F 118 Bytes [ 8B, 46, 34, 53, FF, 75, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqAddressChangeFn + 88 77E9AEC6 101 Bytes [ 39, 3D, D8, B1, EF, 77, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqAddressChangeFn + EE 77E9AF2C 22 Bytes [ 7E, FF, FF, FF, FF, 77, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqAddressChangeFn + 105 77E9AF43 21 Bytes [ FF, 35, E0, B1, EF, 77, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqAddressChangeFn + 11B 77E9AF59 68 Bytes [ 00, 03, 09, 80, 0F, 84, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate + A6 77E9BEEE 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate + AA 77E9BEF2 30 Bytes [ FF, 55, 8B, EC, 83, EC, 30, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate + C9 77E9BF11 45 Bytes [ 4D, D0, 51, 50, FF, 75, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate + F7 77E9BF3F 53 Bytes [ 81, C1, B0, 00, 00, 00, 51, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate + 12D 77E9BF75 4 Bytes [ 45, 0C, 89, 42 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetDcomProtocolVersion + 44 77E9C26E 29 Bytes [ CA, 83, E1, 03, F3, AA, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetDcomProtocolVersion + 62 77E9C28C 131 Bytes JMP 642F8A08
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetDcomProtocolVersion + E6 77E9C310 9 Bytes [ 8D, 4D, F0, 51, 50, E8, 29, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetDcomProtocolVersion + F0 77E9C31A 64 Bytes CALL 7A32482E
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetDcomProtocolVersion + 132 77E9C35C 1 Byte [ 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingFromStringBindingA + 47 77E9C517 24 Bytes [ 33, C0, 5F, 8B, 4D, FC, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeA + 14 77E9C530 126 Bytes [ 01, 00, 00, 00, 01, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeA + 93 77E9C5AF 9 Bytes [ FF, A3, F8, B1, EF, 77, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeA + 9E 77E9C5BA 99 Bytes [ 85, C0, 74, 07, B8, B0, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeA + 103 77E9C61F 3 Bytes [ A6, 92, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcStringBindingComposeA + 107 77E9C623 12 Bytes [ 56, BE, 00, 04, 00, 00, 56, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2A + 3C 77E9CF78 55 Bytes [ 45, 10, 8D, 04, 48, 50, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2A + 74 77E9CFB0 101 Bytes [ 4D, 18, 40, 89, 01, 5F, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2A + DA 77E9D016 10 Bytes [ 33, F6, 56, 68, 40, C0, E9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2A + E6 77E9D022 121 Bytes [ 80, FF, 15, 88, 10, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerUseProtseq2A + 160 77E9D09C 49 Bytes [ 33, C0, EB, F6, 90, 90, 90, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeFormatString + 17 77E9DCF2 47 Bytes [ 8B, 4D, F4, 85, C9, 74, 07, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeFormatString + 48 77E9DD23 24 Bytes [ 74, DB, 8B, 4D, F4, C7, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeFormatString + 61 77E9DD3C 4 Bytes [ C7, 45, FC, 0E ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeFormatString + 66 77E9DD41 5 Bytes [ 07, 80, E9, D2, 3F ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeFormatString + 6D 77E9DD48 21 Bytes [ 83, F8, 42, 0F, 8C, B9, 26, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetTypeFormatString + 13 77E9F4AC 36 Bytes [ 00, 00, 5A, FB, 12, 10, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetTypeGenCookie + 14 77E9F4D1 12 Bytes [ 00, CC, FC, 05, 10, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetTypeGenCookie + 21 77E9F4DE 20 Bytes [ 2A, FB, 0A, 10, 00, 00, 42, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetTypeGenCookie + 36 77E9F4F3 50 Bytes [ 10, 00, 00, 0A, FD, 48, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetProcFormatString + C 77E9F526 5 Bytes [ 9E, FB, 11, 40, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetProcFormatString + 12 77E9F52C 29 Bytes [ 98, FB, 02, 40, 00, 00, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpGetProcFormatString + 30 77E9F54A 79 Bytes [ 42, FB, 17, 40, 00, 00, 3C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpVarVtOfTypeDesc + 4B 77E9F59A 21 Bytes [ FF, FF, 12, 00, 22, FA, 12, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeGenCookie + 11 77E9F5B0 7 Bytes [ 1A, 03, 14, 00, 00, 00, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeGenCookie + 19 77E9F5B8 141 Bytes [ 4C, 00, 06, FA, 4C, 00, 88, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeGenCookie + A7 77E9F646 19 Bytes [ C1, 66, 83, 48, 04, FF, 66, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeGenCookie + BB 77E9F65A 64 Bytes [ 48, 0C, 66, C7, 40, 10, 07, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpReleaseTypeGenCookie + FC 77E9F69B 63 Bytes [ 08, 89, 34, 10, 66, 83, 41, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructFree + 1A 77EA09B5 54 Bytes CALL 77EA0907 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructFree + 51 77EA09EC 24 Bytes JMP 77EA0179 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructFree + 6A 77EA0A05 62 Bytes [ BF, 00, 00, 66, 83, 7D, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructFree + A9 77EA0A44 3 Bytes [ C6, 45, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantStructFree + AD 77EA0A48 18 Bytes JMP 77E9FB6D C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExW + 2 77EA0D5F 15 Bytes [ FF, 81, E7, 00, 40, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExW + 12 77EA0D6F 23 Bytes [ 0F, 84, 85, 08, 00, 00, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExW + 2A 77EA0D87 3 Bytes [ 33, C0, 66 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExW + 2E 77EA0D8B 67 Bytes [ 03, 66, 85, C0, 0F, 85, CD, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExW + 72 77EA0DCF 66 Bytes [ 75, D0, FF, 75, CC, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingCopy + 2 77EA0E12 36 Bytes [ 51, 4C, 8B, 45, FC, 8D, A5, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingCopy + 27 77EA0E37 26 Bytes [ F1, 66, 8B, 48, 04, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingCopy + 43 77EA0E53 3 Bytes [ 1C, 33, DB ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingCopy + 47 77EA0E57 80 Bytes [ 75, 18, 8D, 4D, 0C, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingCopy + 98 77EA0EA8 49 Bytes [ 33, C0, 66, 8B, 07, 8B, CE, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExA + 2F 77EA116A 6 Bytes [ 0C, 39, 75, 08, 77, 03 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExA + 36 77EA1171 15 Bytes [ 75, 08, 8B, 51, 08, 0F, B7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExA + 46 77EA1181 28 Bytes [ 66, 8B, C6, 5E, 5D, C2, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExA + 63 77EA119E 41 Bytes [ C0, 7C, 13, 0F, B7, 4E, 06, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthClientExA + 8D 77EA11C8 115 Bytes [ F8, 06, 75, 4B, 8D, 45, D0, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUnregisterIf + 34 77EA1795 8 Bytes [ 00, 89, 45, FC, E9, 2C, 3C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUnregisterIf + 3D 77EA179E 14 Bytes [ 39, 5D, F0, 0F, 84, 8F, 6A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUnregisterIf + 4F 77EA17B0 37 Bytes [ 83, C0, 74, 50, FF, D7, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUnregisterIf + 75 77EA17D6 7 Bytes [ 51, 8B, 4B, 70, 50, E8, 15 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUnregisterIf + 7E 77EA17DF 15 Bytes [ 00, 85, C0, 89, 43, 6C, 0F, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmDestroyClientContext + 9 77EA18D7 51 Bytes [ 58, 13, E7, 77, 5F, 5E, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsDestroyClientContext + 2 77EA190B 1 Byte [ 59 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsDestroyClientContext + 4 77EA190D 65 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsDestroyClientContext + 46 77EA194F 140 Bytes [ 79, 04, 00, 74, 17, 8B, 41, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsDestroyClientContext + D3 77EA19DC 5 Bytes [ 5F, 5E, 5D, C2, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsDestroyClientContext + D9 77EA19E2 59 Bytes [ B8, DA, BB, E7, 77, E9, 79, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSsDefaultAllocate + 2A 77EA223F 31 Bytes [ 15, 58, 13, E7, 77, 8B, C6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSsDefaultAllocate + 4A 77EA225F 89 Bytes [ B2, EF, 77, FF, 15, 60, 11, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSsDefaultAllocate + A4 77EA22B9 26 Bytes [ 00, F6, 46, 1C, 08, 5E, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSsDefaultAllocate + BF 77EA22D4 13 Bytes JMP 77E8997A C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSsDefaultAllocate + CD 77EA22E2 23 Bytes [ FF, 55, 8B, EC, 56, 8B, F1, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRaiseException + 9 77EA2497 2 Bytes [ 9C, 6E ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRaiseException + D 77EA249B 42 Bytes [ 5F, 5E, 5B, C9, C2, 08, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRaiseException + 38 77EA24C6 17 Bytes [ 00, EB, 24, 90, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRaiseException + 4A 77EA24D8 18 Bytes [ 53, 56, 8B, F1, 57, 8D, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcRaiseException + 5F 77EA24ED 71 Bytes [ 8D, 45, FC, 8B, CE, 50, E8, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcExceptionFilter + 22 77EA29A3 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcExceptionFilter + 2A 77EA29AB 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcExceptionFilter + 2E 77EA29AF 2 Bytes [ 00, 44 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcExceptionFilter + 32 77EA29B3 18 Bytes [ 00, 80, BD, A8, AF, 8A, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcExceptionFilter + 46 77EA29C7 23 Bytes [ 00, 04, 5D, 88, 8A, EB, 1C, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockExclusive + 2C 77EA2CCD 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockExclusive + 3C 77EA2CDD 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockExclusive + 40 77EA2CE1 69 Bytes [ 00, 00, 00, 1D, 00, 08, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockExclusive + 87 77EA2D28 2 Bytes [ 29, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockExclusive + 8A 77EA2D2B 32 Bytes [ 00, 01, 00, FF, FF, FF, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidFromStringW + 1E 77EA32B9 50 Bytes [ 85, C9, 74, 11, 0F, BF, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidEqual + 4 77EA32EC 27 Bytes [ 5D, 0C, 57, 8D, BE, 80, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidEqual + 20 77EA3308 17 Bytes [ 8B, 45, 08, 89, 46, 7C, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidEqual + 3B 77EA3323 4 Bytes [ 8B, 45, 08, 8B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidEqual + 40 77EA3328 23 Bytes [ 83, F9, 01, 74, 18, 83, F9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidEqual + 5E 77EA3346 36 Bytes CALL 77EA3203 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoW 77EA348D 13 Bytes [ 90, 8B, FF, 55, 8B, EC, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoW + E 77EA349B 49 Bytes [ 5D, 90, 90, 90, 90, 90, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoW + 42 77EA34CF 49 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoW + 74 77EA3501 152 Bytes [ 00, 00, 00, AC, B2, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerListen + 2D 77EA359B 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerListen + 31 77EA359F 55 Bytes [ FF, 55, 8B, EC, 83, EC, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerListen + 69 77EA35D7 35 Bytes [ 57, 8B, 7E, 0C, 83, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerListen + 8D 77EA35FB 30 Bytes CALL 77F2B383 C:\WINDOWS\system32\GDI32.dll (GDI Client DLL/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerListen + AC 77EA361A 11 Bytes [ 0D, 28, B5, EF, 77, 8B, F3, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf + 1 77EA3660 2 Bytes [ EC, 56 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf + 4 77EA3663 88 Bytes [ 75, 08, 83, 26, 00, C7, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf + 5D 77EA36BC 37 Bytes [ C0, 74, 04, 66, 89, 70, 2C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf + 85 77EA36E4 24 Bytes [ 5E, 5D, C2, 04, 00, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerRegisterIf + 9E 77EA36FD 9 Bytes [ D8, 85, DB, 74, 4C, 53, E8, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayFree + 13 77EA3E9C 34 Bytes [ 4E, 0A, 51, 83, C0, 02, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayFree + 36 77EA3EBF 263 Bytes [ 00, 00, 85, C0, 74, 36, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMarshall + 62 77EA3FC7 8 Bytes [ EF, 18, 6A, 0F, 5A, 23, FA, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMarshall + 6B 77EA3FD0 9 Bytes [ 3C, 7D, 70, B5, EF, 77, 66, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMarshall + 75 77EA3FDA 1 Byte [ F9 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMarshall + 77 77EA3FDC 17 Bytes [ EF, 14, 23, FA, 66, 8B, 3C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMarshall + 89 77EA3FEE 92 Bytes [ F9, C1, EF, 10, 23, FA, 66, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayUnmarshall + 34 77EA404B 137 Bytes [ 08, 5F, 03, C6, 5E, 5D, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayUnmarshall + BE 77EA40D5 12 Bytes [ 2D, 00, 66, 8B, 4E, 06, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayUnmarshall + CB 77EA40E2 41 Bytes [ FF, 8B, C8, 66, C7, 01, 2D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayUnmarshall + F5 77EA410C 10 Bytes [ B6, 46, 0A, 83, C1, 02, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayUnmarshall + 100 77EA4117 23 Bytes [ 8B, C8, 66, 0F, B6, 46, 0B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMemorySize + 76 77EA4228 3 Bytes [ 84, F1, B0 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMemorySize + 7B 77EA422D 5 Bytes [ FF, 75, 08, 66, 89 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMemorySize + 174 77EA4326 4 Bytes [ 7D, 08, 6A, 10 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMemorySize + 179 77EA432B 3 Bytes [ F1, 59, 33 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrVaryingArrayMemorySize + 17D 77EA432F 8 Bytes [ F3, A6, 5F, 5E, 74, 05, 1B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStopServerListening + D 77EA4864 4 Bytes [ 00, 83, 7D, FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStopServerListening + 12 77EA4869 4 Bytes [ 0F, 85, B3, 92 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStopServerListening + 17 77EA486E 4 Bytes [ 00, 89, BE, 8C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStopServerListening + 5F 77EA48B6 92 Bytes [ 51, 02, 8A, 09, 8B, 75, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtStopServerListening + BC 77EA4913 73 Bytes [ 53, FF, 15, 58, 13, E7, 77, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalMemorySize + 15 77EA4A0D 198 Bytes [ 00, 8B, 88, 90, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayMemorySize + 4C 77EA4AFE 3 Bytes [ 85, 4F, 10 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayMemorySize + 51 77EA4B03 41 Bytes [ 8B, 4D, 08, 8D, 45, FC, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayMemorySize + 7B 77EA4B2D 22 Bytes [ 8B, 45, 08, 8B, 48, 0C, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayMemorySize + 92 77EA4B44 4 Bytes [ D1, 83, 4D, FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrFixedArrayMemorySize + A8 77EA4B5A 38 Bytes JMP EAF72D77
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorStartEnumeration + 6F 77EA4D34 17 Bytes CALL 77EA4D50 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorStartEnumeration + 81 77EA4D46 79 Bytes [ 00, 01, 00, 00, 00, 5E, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorStartEnumeration + D1 77EA4D96 13 Bytes [ 75, 15, FF, 75, 10, FF, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorStartEnumeration + DF 77EA4DA4 1 Byte [ C0 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorStartEnumeration + E1 77EA4DA6 169 Bytes [ 59, 0F, 84, AF, 28, FF, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!GlobalMutexClearExternal + 24 77EB5812 92 Bytes JMP 77E9B4EE C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!GlobalMutexClearExternal + 81 77EB586F 10 Bytes [ FE, FF, 66, 89, 5F, 02, C7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!GlobalMutexClearExternal + 8C 77EB587A 6 Bytes [ 00, 00, E9, 5D, 59, FE ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!GlobalMutexClearExternal + BB 77EB58A9 5 Bytes JMP 77E9B20A C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!GlobalMutexClearExternal + D1 77EB58BF 43 Bytes [ 15, 5C, 12, E7, 77, E9, E8, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcNsInterfaceUnexported + B 77EB6528 75 Bytes [ D2, D6, ED, 77, E0, ED, ED, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNetworkIsProtseqValidW + 21 77EB6574 23 Bytes [ 32, 00, 33, 00, 34, 00, 35, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextA + 13 77EB658C 1 Byte [ 45 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextA + 15 77EB658E 6 Bytes [ 46, 00, 0D, 0A, 0D, 0A ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextA + 1C 77EB6595 16 Bytes [ 90, 90, 90, 48, 54, 54, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextA + 2D 77EB65A6 57 Bytes [ 75, 63, 63, 65, 73, 73, 0D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextW + 13 77EB65E0 1 Byte [ 18 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextW + 16 77EB65E3 7 Bytes [ 00, 04, 00, 00, 00, 10, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextW + 1F 77EB65EC 22 Bytes [ 04, 00, 00, 00, 04, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DceErrorInqTextW + 37 77EB6604 301 Bytes [ 00, 00, 00, 00, 18, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcAsyncAbortCall + 1E 77EB6732 94 Bytes [ 70, 53, 65, 6E, 64, 52, 65, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpResolveBinding + 2A 77EB6791 9 Bytes [ 74, 70, 53, 65, 74, 53, 74, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpResolveBinding + 34 77EB679B 46 Bytes [ 73, 43, 61, 6C, 6C, 62, 61, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameW + 1D 77EB67CA 1 Byte [ 74 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameW + 1F 77EB67CC 22 Bytes [ 74, 00, 70, 00, 3A, 00, 2F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameW + 36 77EB67E3 24 Bytes [ 15, 5C, 13, E7, 77, C3, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcNsBindingSetEntryNameA + C 77EB67FF 282 Bytes [ 8B, FF, 55, 8B, EC, 56, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoW + 3D 77EB691A 64 Bytes [ FF, F7, D8, 1B, C0, 83, E0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoW + 7E 77EB695B 7 Bytes [ 3B, C7, 75, 79, 39, BE, DC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoW + 88 77EB6965 78 Bytes [ 74, 6F, 53, 68, 78, B0, EF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoW + D7 77EB69B4 42 Bytes [ 77, 04, FF, 50, 18, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoW + 105 77EB69E2 16 Bytes [ 90, 8B, FF, 55, 8B, EC, 51, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeMarshall + 3F 77EB6A73 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeMarshall + 45 77EB6A79 11 Bytes [ FF, 55, 8B, EC, 83, EC, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeMarshall + 51 77EB6A85 61 Bytes [ 56, 57, 8B, 3D, 5C, 13, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeMarshall + 8F 77EB6AC3 30 Bytes [ 16, 8D, 4D, F8, 51, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializeMarshall + AE 77EB6AE2 64 Bytes [ 75, 05, 6A, 0E, 58, EB, 3D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqWireIdForSnego + 2 77EB6E6C 21 Bytes [ 8B, F0, 85, F6, 75, E1, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqWireIdForSnego + 18 77EB6E82 72 Bytes [ FF, 55, 8B, EC, 83, EC, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingHandleToAsyncHandle + 21 77EB6ECB 9 Bytes [ FF, FF, 3B, C7, 74, 0C, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingHandleToAsyncHandle + 2B 77EB6ED5 15 Bytes [ 05, 33, DB, 39, 7E, 08, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingHandleToAsyncHandle + 3B 77EB6EE5 97 Bytes [ 75, 03, 83, C3, F1, 8B, 4D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingHandleToAsyncHandle + 9D 77EB6F47 23 Bytes [ 40, 10, 8B, 4D, 0C, 89, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingHandleToAsyncHandle + B5 77EB6F5F 36 Bytes [ 75, 07, BE, B4, 06, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransIoCancelled + 1C 77EB7762 86 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransIoCancelled + ED 77EB7833 22 Bytes [ 4D, 08, FF, 75, 0C, E8, 3C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransIoCancelled + 104 77EB784A 112 Bytes [ EC, 83, 3D, DC, B0, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransIoCancelled + 1BC 77EB7902 12 Bytes [ 75, 10, FF, 75, 0C, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransIoCancelled + 1C9 77EB790F 12 Bytes [ 5D, C2, 18, 00, 90, 90, 90, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqDefaultProtectLevel + 2 77EB8A71 182 Bytes [ 85, C0, 74, C1, 6A, 0E, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqOption + 48 77EB8B28 18 Bytes [ FF, 85, C0, 74, 12, 8B, 4E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqConnId + 4 77EB8B3B 43 Bytes [ CE, FF, 50, 10, 5E, 5D, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqConnId + 30 77EB8B67 46 Bytes [ 00, 00, 01, 74, 07, BE, A5, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqConnId + 5F 77EB8B96 15 Bytes CALL 77EA20C8 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqConnId + 6F 77EB8BA6 4 Bytes [ 00, 01, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqConnId + 74 77EB8BAB 63 Bytes CALL 77E95331 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcObjectInqType + 26 77EB8CAD 105 Bytes [ 50, 10, 5F, 5E, C9, C3, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcObjectSetType + 1C 77EB8D17 4 Bytes [ 89, BE, 78, 01 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcObjectSetType + 21 77EB8D1C 89 Bytes [ 00, 75, D0, 8B, 4E, 14, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqIf + 1 77EB8D76 132 Bytes [ D9, 89, 7D, F8, 89, 7D, FC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqStats + 1 77EB8DFB 151 Bytes [ 75, 08, EB, 3C, 8B, 43, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqStats + 99 77EB8E93 44 Bytes CALL 77EA5735 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqStats + C6 77EB8EC0 97 Bytes [ FF, 76, 0C, 8D, 8B, FC, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqStats + 128 77EB8F22 58 Bytes [ FF, 85, C0, 89, 45, FC, 74, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqStats + 163 77EB8F5D 28 Bytes [ 8D, 83, D4, 00, 00, 00, 50, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcGetAuthorizationContextForClient + 4F 77EB91A7 50 Bytes [ 00, 89, 08, 8B, 45, 08, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcGetAuthorizationContextForClient + 82 77EB91DA 25 Bytes [ 74, 08, 8B, 4E, 50, E8, E6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcGetAuthorizationContextForClient + 9C 77EB91F4 41 Bytes [ 55, 8B, EC, 53, 56, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcFreeAuthorizationContext + 1 77EB921E 375 Bytes CALL C050062C
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqLocalConnAddress + 1 77EB93F8 100 Bytes [ 06, 6A, 02, 8B, CE, FF, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqLocalConnAddress + 66 77EB945D 41 Bytes [ 08, 8B, 46, 28, 25, 00, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsEx + 16 77EB9487 39 Bytes [ 09, 74, 52, 48, 74, 43, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsEx + 3E 77EB94AF 24 Bytes [ 8B, 4E, 0C, 3B, 4D, 0C, 73, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsEx + 58 77EB94C9 91 Bytes CALL 77EA5737 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsEx + B4 77EB9525 40 Bytes [ 55, 8B, EC, 83, EC, 30, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqsEx + DD 77EB954E 61 Bytes [ 85, C0, 74, 08, 50, 8B, CE, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqs + 10 77EB95F5 12 Bytes [ 00, 53, FF, 15, 5C, 13, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseAllProtseqs + 1E 77EB9603 149 Bytes CALL 77E8B6CC C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesW + 85 77EB9699 139 Bytes [ 7D, 0C, 75, 0C, FF, 77, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSessionStrictContextHandle + 7C 77EB9725 9 Bytes [ 89, 5E, 68, 8B, 47, 08, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSessionStrictContextHandle + 86 77EB972F 32 Bytes [ 47, 0C, 53, 89, 46, 6C, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSessionStrictContextHandle + A7 77EB9750 26 Bytes [ 75, 20, C7, 45, 0C, BE, 06, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSessionStrictContextHandle + C2 77EB976B 14 Bytes [ 95, 7E, FC, FF, 89, 45, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSessionStrictContextHandle + D1 77EB977A 33 Bytes CALL 78DC5602
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcDeleteMutex + 6 77EBA688 5 Bytes [ 78, 10, 3B, FB, 75 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcDeleteMutex + C 77EBA68E 84 Bytes [ B8, BD, 06, 00, 00, EB, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcEnableWmiTrace + 45 77EBA6E3 157 Bytes [ 16, FF, 30, 83, C1, 10, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcEnableWmiTrace + E3 77EBA781 34 Bytes [ EB, 13, FF, 75, 14, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcEnableWmiTrace + 106 77EBA7A4 35 Bytes [ EC, 8B, 45, 0C, 56, 8B, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcEnableWmiTrace + 12A 77EBA7C8 129 Bytes [ 85, DB, 74, 33, 57, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcEnableWmiTrace + 1AC 77EBA84A 29 Bytes [ 00, 00, 8D, 4D, 08, 51, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreePipeBuffer + 1B 77EBA86A 27 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcFreePipeBuffer + 37 77EBA886 70 Bytes [ 8B, FF, 55, 8B, EC, 51, 51, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcReallocPipeBuffer + 1F 77EBA8CE 104 Bytes [ 73, 08, 8B, F8, 8B, C1, C1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqTransportType + 33 77EBA938 78 Bytes [ 33, C9, 43, 39, 4D, 08, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqTransportType + 82 77EBA987 49 Bytes [ 89, 5D, F4, 75, 03, 89, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerInqTransportType + 107 77EBAA0C 42 Bytes [ 15, 84, 11, E7, 77, E9, 9C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerYield + 23 77EBAA37 61 Bytes [ 10, FF, 75, 0C, 68, 64, 4A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerTestCancel + 21 77EBAA75 41 Bytes [ 8B, 40, 18, 89, 03, 33, DB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerTestCancel + 4B 77EBAA9F 9 Bytes [ 15, 70, 11, E7, 77, 50, 68, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerTestCancel + 55 77EBAAA9 87 Bytes CALL 77E98021 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcGetExtendedError + 46 77EBAB01 40 Bytes [ 00, 81, C1, 20, 01, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThread + 1A 77EBAB2A 24 Bytes [ C0, 58, 50, FF, 15, 5C, 11, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThreadEx + B 77EBAB43 30 Bytes [ 00, 90, 90, 90, 90, 90, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThreadEx + 2A 77EBAB62 23 Bytes [ 45, 0C, 83, 20, 00, EB, 3D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThreadEx + 42 77EBAB7A 81 Bytes CALL 77E98025 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThreadEx + 94 77EBABCC 83 Bytes [ FE, FF, C9, C2, 08, 00, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCancelThreadEx + E8 77EBAC20 42 Bytes [ 89, 85, EC, FE, FF, FF, 50, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerAllocateIpPort + 2 77EBBA94 46 Bytes [ 50, 60, F7, D8, 1B, C0, 25, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerAllocateIpPort + 31 77EBBAC3 29 Bytes [ 04, 6A, 0E, 58, C3, 8B, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerAllocateIpPort + 4F 77EBBAE1 41 Bytes [ B2, FE, FF, FF, C2, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcServerAllocateIpPort + 79 77EBBB0B 100 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNetworkIsProtseqValidA + 25 77EBBB70 57 Bytes [ 75, 5E, 8D, 45, FC, 50, 68, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExA + 7 77EBBBAB 1 Byte [ FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExA + 9 77EBBBAD 14 Bytes [ 15, 84, 10, E7, 77, 8B, F0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExA + 18 77EBBBBC 2 Bytes [ 15, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqExA + 1B 77EBBBBF 49 Bytes [ E7, 77, 83, FE, 02, 75, 20, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExA + 2C 77EBBBF1 3 Bytes [ 5C, 36, FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfExA + 30 77EBBBF5 48 Bytes [ FF, 75, FC, 8B, F0, FF, 15, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfA + C 77EBBC26 8 Bytes [ 00, 00, 90, 90, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfA + 15 77EBBC2F 7 Bytes [ 55, 8B, EC, 81, EC, 08, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfA + 1E 77EBBC38 13 Bytes [ A1, AC, B2, EF, 77, 56, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerUseProtseqIfA + 2C 77EBBC46 10 Bytes [ FF, 50, 68, 19, 00, 02, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameA + 2 77EBBC51 20 Bytes [ 35, D0, B6, EF, 77, C7, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameA + 17 77EBBC66 5 Bytes [ B5, 14, FE, FF, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameA + 1D 77EBBC6C 45 Bytes [ 15, 88, 10, E7, 77, 85, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameA + 4B 77EBBC9A 6 Bytes [ FF, 50, 8D, 85, 24, FE ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNsBindingInqEntryNameA + 52 77EBBCA1 5 Bytes [ FF, 50, 50, 50, 56 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidToStringA + 4E 77EBBD38 10 Bytes [ C7, 85, 10, FE, FF, FF, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesA + 2 77EBBD43 13 Bytes [ B5, 1C, FE, FF, FF, C7, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesA + 10 77EBBD51 15 Bytes [ 00, FF, 15, 7C, 10, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesA + 20 77EBBD61 17 Bytes [ 85, 10, FE, FF, FF, 40, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesA + 32 77EBBD73 2 Bytes [ FF, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcServerInqCallAttributesA + 35 77EBBD76 43 Bytes [ 8D, 78, 01, 8A, 08, 40, 84, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingInqAuthInfoExA + 62 77EBBF16 44 Bytes [ 75, 08, 57, 8D, 8D, B0, FE, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExA + D 77EBBF43 34 Bytes [ FF, 89, BD, B8, FE, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExA + 30 77EBBF66 45 Bytes [ 8D, 85, AC, FE, FF, FF, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExA + 5E 77EBBF94 34 Bytes [ 45, BC, 50, FF, B5, B0, FE, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExA + 81 77EBBFB7 6 Bytes [ 02, 8B, 85, B8, FE, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoExA + 88 77EBBFBE 13 Bytes [ 8D, 04, 85, 04, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqServerPrincNameA + 29 77EBC0FF 39 Bytes [ FF, FF, 33, FF, FF, B5, B0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqServerPrincNameA + 51 77EBC127 16 Bytes [ 15, 90, 10, E7, 77, 56, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtInqServerPrincNameA + 62 77EBC138 78 Bytes [ D8, 72, E7, 77, D0, EA, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameA + 4C 77EBC187 28 Bytes [ 20, 7C, F2, 53, BB, A8, F4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNetworkInqProtseqsA + 4 77EBC1A4 41 Bytes [ 44, 07, 04, 85, C0, 74, 21, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNetworkInqProtseqsA + 2E 77EBC1CE 3 Bytes [ 4F, DB, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcNetworkInqProtseqsA + 32 77EBC1D2 72 Bytes [ 6A, 0E, 58, EB, EE, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidFromStringA + 1B 77EBC21C 90 Bytes [ 14, C6, 04, 06, 01, 46, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidFromStringA + 76 77EBC277 109 Bytes [ C0, 03, 57, 83, E0, FC, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoA + 2 77EBC2E5 8 Bytes [ 75, F8, 50, 56, 51, E8, ED, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoA + B 77EBC2EE 21 Bytes [ FF, 8B, 4D, 08, 03, F8, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoA + 21 77EBC304 82 Bytes [ 7E, 19, 53, FF, 75, FC, 53, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoA + 74 77EBC357 26 Bytes [ 6A, 0E, 58, EB, 7C, 89, 30, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcBindingSetAuthInfoA + 8F 77EBC372 53 Bytes [ 4C, 81, 04, 8B, 37, 89, 4C, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate2 + 88 77EBCCD0 21 Bytes [ 08, 74, 09, FF, 75, FC, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate2 + A1 77EBCCE9 159 Bytes [ 90, 8B, FF, 55, 8B, EC, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate2 + 141 77EBCD89 39 Bytes [ 02, 53, 57, 74, 3C, 8B, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate2 + 169 77EBCDB1 19 Bytes [ 0C, 74, 09, FF, 75, FC, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramAllocate2 + 17D 77EBCDC5 13 Bytes [ 89, 7D, F8, EB, 06, 8B, 7D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramFree + 5A 77EBD67C 4 Bytes [ 48, 08, 0F, C9 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramFree + 5F 77EBD681 15 Bytes [ 48, 08, 66, 8B, 48, 0C, 66, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramFree + 6F 77EBD691 57 Bytes [ 48, 0E, 66, 89, 50, 0C, 8A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramFree + A9 77EBD6CB 260 Bytes [ 55, 8B, EC, 8B, 45, 08, F6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcTransDatagramFree + 1AE 77EBD7D0 74 Bytes [ D1, 89, 45, EC, 73, 1D, 8D, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCompare + 44 77EBEF5D 1 Byte [ EC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!UuidCompare + 46 77EBEF5F 118 Bytes [ C1, 8B, 48, 5C, 8B, 49, 64, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncGetCallStatus + 1E 77EBEFD7 2 Bytes [ 74, 1A ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncGetCallStatus + 21 77EBEFDA 4 Bytes [ 00, 83, C0, 18 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncGetCallStatus + 26 77EBEFDF 31 Bytes CALL 77E941E1 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncGetCallStatus + 46 77EBEFFF 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncGetCallStatus + 49 77EBF002 32 Bytes [ EC, FF, 75, 08, 8D, 81, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncCancelCall 77EBF025 5 Bytes [ 90, 90, 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncCancelCall + 6 77EBF02B 3 Bytes [ EC, 56, 57 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncCancelCall + A 77EBF02F 59 Bytes [ F1, 8D, BE, EC, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncCancelCall + 49 77EBF06E 82 Bytes [ 90, 8B, FF, 55, 8B, EC, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcAsyncCancelCall + 9C 77EBF0C1 23 Bytes [ FF, 90, 90, 90, 90, 90, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameW + 2 77EBFAA9 75 Bytes [ 50, 60, 85, C0, 74, 04, 80, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameW + 4E 77EBFAF5 29 Bytes [ 74, 13, 05, EC, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameW + 6C 77EBFB13 152 Bytes [ 75, EC, FF, B6, C0, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameW + 105 77EBFBAC 8 Bytes [ FF, 75, FC, 8B, CB, 57, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcCertGeneratePrincipalNameW + 145 77EBFBEC 20 Bytes [ 7D, 08, 57, 8D, 8E, 68, 01, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterNoReplaceA + 16 77EBFEB3 120 Bytes [ 0C, 8B, 4D, 08, 83, 20, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterNoReplaceA + 8F 77EBFF2C 61 Bytes [ FF, FF, 8B, 7D, 0C, 8B, D8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpRegisterNoReplaceW + 23 77EBFF6A 79 Bytes [ 4F, 04, 66, 3B, C8, 75, 2C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpUnregister + 1B 77EBFFBA 43 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpUnregister + 48 77EBFFE7 22 Bytes [ 5E, 5D, C2, 04, 00, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpUnregister + 5F 77EBFFFE 90 Bytes [ 8B, 70, 04, 8B, 4E, 24, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpUnregister + BA 77EC0059 129 Bytes [ CE, FF, 50, 54, EB, 05, B8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcEpUnregister + 13C 77EC00DB 29 Bytes [ 8B, DC, 56, 53, FF, 75, 10, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorGetNextRecord + 1 77EC0878 5 Bytes [ F8, 85, FF, 75, 23 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorGetNextRecord + 8 77EC087F 55 Bytes [ 0C, 83, FF, 01, 75, 33, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorGetNextRecord + 40 77EC08B7 106 Bytes [ 00, 8B, C7, C1, E0, 02, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorSaveErrorInfo + D 77EC0922 49 Bytes [ 45, 0C, 3B, 45, F8, 72, CF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorSaveErrorInfo + 3F 77EC0954 83 Bytes CALL 77EA36EB C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorSaveErrorInfo + 93 77EC09A8 3 Bytes [ 42, 2D, FE ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorSaveErrorInfo + 97 77EC09AC 57 Bytes [ 56, FF, 75, 0C, FF, 15, 98, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorSaveErrorInfo + D1 77EC09E6 146 Bytes [ 47, 0C, 56, 83, C0, 18, 50, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorLoadErrorInfo + 2 77EC0F70 22 Bytes [ 75, FC, FF, 75, 10, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorLoadErrorInfo + 19 77EC0F87 19 Bytes [ 74, 0A, 8D, 45, F8, 50, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorLoadErrorInfo + 2E 77EC0F9C 20 Bytes [ 90, 90, 90, 6A, 50, 68, 60, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorLoadErrorInfo + 44 77EC0FB2 2 Bytes [ E4, 8B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorLoadErrorInfo + 47 77EC0FB5 1 Byte [ 08 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorAddRecord + 7 77EC14A6 44 Bytes [ 40, 30, 6A, 00, FF, 70, 18, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorAddRecord + 34 77EC14D3 17 Bytes [ 43, 4E, 74, 38, 4E, 74, 2B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorAddRecord + 46 77EC14E5 80 Bytes [ 58, EB, 49, 83, C2, 08, 52, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorClearInformation + B 77EC1536 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorClearInformation + 11 77EC153C 165 Bytes [ FF, 55, 8B, EC, 8B, 4D, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorClearInformation + B7 77EC15E2 41 Bytes [ 56, 8B, 75, 10, 56, E8, 70, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorClearInformation + E1 77EC160C 39 Bytes [ 00, 66, 89, 46, 28, 0F, BF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcErrorClearInformation + 109 77EC1634 37 Bytes [ 08, 03, C3, 50, 53, E8, 7E, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqBegin + 41 77EC17E9 179 Bytes [ 3A, 49, 74, 2D, 49, 74, 1C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqBegin + F5 77EC189D 34 Bytes [ 75, 10, FF, 75, 0C, 56, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqBegin + 118 77EC18C0 139 Bytes [ EC, 8B, 45, 08, 81, 38, FC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqBegin + 1A4 77EC194C 149 Bytes [ 46, 08, 89, 45, D8, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqDone + 48 77EC19E2 52 Bytes CALL FBB89772
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextA + 31 77EC1A17 99 Bytes [ 3C, 16, 8B, D1, C1, E9, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextA + 95 77EC1A7B 4 Bytes [ 70, 75, FB, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextA + 9A 77EC1A80 47 Bytes [ 65, E4, 00, 8D, 45, E4, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextA + CB 77EC1AB1 26 Bytes [ F0, 89, 75, D4, 85, F6, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextA + E6 77EC1ACC 23 Bytes [ 6A, 01, FF, 75, E4, E8, 86, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpUnregister + 5F 77EC1CE0 6 Bytes [ 8B, 00, 89, 45, DC, 50 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpUnregister + 66 77EC1CE7 3 Bytes [ 96, 1C, FE ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpUnregister + 6A 77EC1CEB 26 Bytes [ C3, 90, 90, 90, 90, 90, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpUnregister + 85 77EC1D06 135 Bytes [ 08, 8B, 45, 10, 8B, 4D, E0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpUnregister + 10D 77EC1D8E 3 Bytes [ B2, B1, FD ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextW + 1B 77EC1EEC 77 Bytes [ D8, 8B, 45, 0C, 89, 18, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtEpEltInqNextW + 69 77EC1F3A 65 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetAuthorizationFn + 5E 77EC1F9C 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetAuthorizationFn + 62 77EC1FA0 62 Bytes [ EC, 83, EC, 40, 8B, 4D, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetAuthorizationFn + A1 77EC1FDF 3 Bytes [ 0B, 17, FE ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetAuthorizationFn + A5 77EC1FE3 10 Bytes [ C9, C2, 1C, 00, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcMgmtSetAuthorizationFn + B0 77EC1FEE 31 Bytes [ 55, 8B, EC, 83, EC, 20, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCreateServerInterfaceFromStub + 5 77EC9118 30 Bytes [ 17, 53, EC, 77, 89, B6, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCreateServerInterfaceFromStub + 34 77EC9147 5 Bytes [ 8D, 46, 2C, 50, 89 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCreateServerInterfaceFromStub + 3B 77EC914E 23 Bytes [ FF, 15, 5C, 13, E7, 77, 39, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCreateServerInterfaceFromStub + 53 77EC9166 34 Bytes [ 75, FC, 8B, 35, 58, 13, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrCreateServerInterfaceFromStub + 76 77EC9189 42 Bytes [ 78, 0C, 8B, 48, 08, 6B, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointA + 68 77ECA906 19 Bytes [ FF, 56, 8B, F1, 8B, 46, 3C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointA + 7C 77ECA91A 25 Bytes [ 59, 8D, 4E, 14, 5E, E9, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointA + 96 77ECA934 55 Bytes [ 77, 18, 8B, 4D, 08, 8B, 1E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointA + CF 77ECA96D 240 Bytes [ 7D, 08, 8B, F1, 6A, 00, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcBindingInqDynamicEndpointA + 1C1 77ECAA5F 1 Byte [ 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcSsDontSerializeContext + 8 77ECF6DD 113 Bytes [ 8D, 4D, F4, 51, 8D, 4D, F0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockShared + 6A 77ECF74F 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockShared + 6E 77ECF753 38 Bytes [ 8E, 7C, 02, 00, 00, 0F, B6, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockShared + 96 77ECF77B 56 Bytes [ 74, 09, F6, 86, 90, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockShared + CF 77ECF7B4 160 Bytes [ 00, 38, 5F, 19, 57, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsContextLockShared + 170 77ECF855 58 Bytes [ C6, 40, 6B, 01, FF, 75, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshallEx + B 77ECF8DA 7 Bytes [ 57, 8D, 4E, 4C, E8, C3, 8C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NDRSContextUnmarshallEx + 13 77ECF8E2 232 Bytes [ FF, 81, 7D, FC, 08, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsGetContextBinding 77ECF9CF 196 Bytes [ 8B, FF, 55, 8B, EC, 53, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsGetContextBinding + C5 77ECFA94 6 Bytes [ 8E, 7C, 02, 00, 00, E8 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsGetContextBinding + CC 77ECFA9B 34 Bytes [ D1, FF, FF, B8, 79, 07, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_from_ndr + 41 77ECFB13 21 Bytes [ DB, 74, E3, 85, DB, 8B, 86, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_from_ndr + 58 77ECFB2A 17 Bytes [ 01, 09, 00, 00, 75, 12, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_from_ndr + 6A 77ECFB3C 8 Bytes [ 58, 13, E7, 77, EB, 0F, 53, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_from_ndr + EB 77ECFBBD 60 Bytes [ FF, 8B, F8, 85, FF, 74, D9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_from_ndr + 187 77ECFC59 12 Bytes CALL FCECFC5E
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_size_ndr + 5B 77ECFF69 97 Bytes [ 7E, 3C, 00, 74, 26, 57, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_size_ndr + BD 77ECFFCB 15 Bytes [ 15, 5C, 13, E7, 77, 8B, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_size_ndr + CD 77ECFFDB 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_size_ndr + CF 77ECFFDD 99 Bytes [ 00, FF, 15, 90, 11, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_size_ndr + 133 77ED0041 62 Bytes [ 75, F4, FF, 55, F0, 83, 7F, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_size_ndr + D 77ED00D4 60 Bytes [ F3, 89, 5E, 10, 8B, 4B, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_size_ndr + 4B 77ED0112 35 Bytes [ EB, 12, 39, 77, 28, 75, 0D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_size_ndr + 70 77ED0137 1 Byte [ 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_size_ndr + 72 77ED0139 6 Bytes [ 90, 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_size_ndr + 79 77ED0140 69 Bytes [ 55, 8B, EC, 8B, 4D, 08, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_peek_ndr + 86 77ED02E6 51 Bytes [ C6, 22, 56, FF, 75, 10, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_peek_ndr + BA 77ED031A 37 Bytes [ 75, F8, 6A, 10, 56, FF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_peek_ndr + E0 77ED0340 26 Bytes [ 74, 00, 72, 00, 6F, 00, 6C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_peek_ndr + FB 77ED035B 105 Bytes [ 55, 8B, EC, 8D, 45, 04, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_peek_ndr + 165 77ED03C5 2 Bytes [ 5D, C2 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_into_ndr + C 77ED041D 40 Bytes [ FF, 55, 8B, EC, 8D, 45, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_into_ndr + 35 77ED0446 44 Bytes [ 8B, EC, 8D, 45, 04, 83, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_into_ndr + 62 77ED0473 123 Bytes [ C0, 04, 50, 68, 60, 38, E9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_into_ndr + DE 77ED04EF 33 Bytes JMP 4FD6E877
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!data_into_ndr + 100 77ED0511 15 Bytes JMP 92756D8D
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_into_ndr + 5 77ED064A 2 Bytes [ 77, E8 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_into_ndr + 8 77ED064D 2 Bytes [ 4E, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_into_ndr + B 77ED0650 68 Bytes [ 83, C4, 0C, 5D, C2, 08, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_into_ndr + 51 77ED0696 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!tree_into_ndr + 7E 77ED06C3 5 Bytes [ 00, 00, 00, 00, 00 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_from_ndr + 30 77ED08CA 127 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_array_from_ndr + 43 77ED094A 1 Byte [ 48 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_array_from_ndr + 45 77ED094C 23 Bytes [ 75, 0B, 0F, B6, 09, 8A, 89, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_array_from_ndr + 5D 77ED0964 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_array_from_ndr + 63 77ED096A 58 Bytes [ FF, 55, 8B, EC, 8B, 55, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!float_array_from_ndr + 9E 77ED09A5 37 Bytes [ 4D, 10, 73, 17, EB, E8, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_from_ndr 77ED09CD 19 Bytes [ 90, 90, 6A, 0C, 68, 38, FA, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_from_ndr + 14 77ED09E1 39 Bytes [ 4D, 08, 81, 79, 04, 98, BA, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_from_ndr + 3C 77ED0A09 28 Bytes [ 3D, 05, 00, 00, C0, 74, 0A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_from_ndr + 59 77ED0A26 36 Bytes [ 6A, 57, 58, 83, 4D, FC, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_from_ndr + 7E 77ED0A4B 83 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!double_array_from_ndr + 4F 77ED0A9F 120 Bytes [ 5E, 5D, C2, 08, 00, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!short_from_ndr + 1 77ED0B18 2 Bytes [ 45, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!short_from_ndr + 4 77ED0B1B 84 Bytes [ 7D, 10, 0F, BE, 0F, 47, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!short_array_from_ndr + 1E 77ED0B70 55 Bytes [ 4D, F8, EB, 06, 8B, CE, EB, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!short_array_from_ndr + 56 77ED0BA8 66 Bytes [ C3, 07, 83, E3, F8, E9, 6B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!short_from_ndr_temp + 2B 77ED0BEB 14 Bytes JMP C9721AF3
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_from_ndr + 1 77ED0BFA 32 Bytes [ 0B, 89, 4D, 14, 83, C3, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_from_ndr + 22 77ED0C1B 35 Bytes [ E3, FE, 8B, CA, F7, D1, 23, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_array_from_ndr + 15 77ED0C3F 36 Bytes [ 89, 4D, 0C, 8B, 0B, 83, C3, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_array_from_ndr + 3A 77ED0C64 25 Bytes [ CA, 8B, 55, F4, 83, E1, 03, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_array_from_ndr + 54 77ED0C7E 58 Bytes [ CE, F7, D1, 23, C1, 83, C3, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!long_from_ndr_temp + 21 77ED0CB9 76 Bytes [ C3, 03, 8B, CE, 03, C6, F7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!enum_from_ndr + 3F 77ED0D06 3 Bytes [ 8B, 45, 08 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!enum_from_ndr + 43 77ED0D0A 1 Byte [ 48 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!enum_from_ndr + 45 77ED0D0C 8 Bytes [ 41, 83, E1, FE, EB, 7F, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!enum_from_ndr + 4F 77ED0D16 53 Bytes CALL 6FC5104C
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!enum_from_ndr + 85 77ED0D4C 102 Bytes [ 48, 08, 83, C1, 03, 83, E1, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllGetClassObject + 2B 77ED2414 10 Bytes [ EC, 8B, 45, 08, 05, 20, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllGetClassObject + 36 77ED241F 3 Bytes [ 37, FC, FF ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllGetClassObject + 3A 77ED2423 40 Bytes [ 5D, C2, 04, 00, 90, 90, 90, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllGetClassObject + 63 77ED244C 4 Bytes [ EC, 53, 8B, 5D ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllGetClassObject + 68 77ED2451 76 Bytes [ 56, 57, 8D, 73, F8, 8D, 46, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!DllRegisterServer + B 77ED2E1C 188 Bytes [ 07, 80, 83, 4D, FC, FF, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllRegisterProxy + 10 77ED2ED9 122 Bytes [ 10, 56, FF, 50, 10, 5B, 5F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllRegisterProxy + 8B 77ED2F54 166 Bytes [ 56, FF, 51, 0C, 89, 45, E4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllRegisterProxy + 132 77ED2FFB 182 Bytes [ 3F, 8B, 0E, 33, C0, 50, 6A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllRegisterProxy + 1E9 77ED30B2 104 Bytes [ FF, 33, F6, 5F, 8B, C6, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllRegisterProxy + 252 77ED311B 66 Bytes [ 90, 90, 90, 90, 90, 83, 6C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllUnregisterProxy + 15 77ED315E 1 Byte [ 5D ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllUnregisterProxy + 17 77ED3160 59 Bytes [ 89, 18, 8D, 7D, D4, A5, A5, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllUnregisterProxy + 53 77ED319C 150 Bytes [ 75, CC, 8D, 4D, D4, 51, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllUnregisterProxy + EA 77ED3233 91 Bytes [ D8, EB, 02, 33, DB, 89, 5D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrDllUnregisterProxy + 146 77ED328F 159 Bytes [ 7C, 54, 66, 39, 75, E0, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesIncrementalHandleReset + 35 77ED332F 41 Bytes [ 16, 8B, 06, FF, 75, 14, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesIncrementalHandleReset + 5F 77ED3359 139 Bytes [ 5D, C4, 6A, 01, 8B, CB, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesIncrementalHandleReset + ED 77ED33E7 88 Bytes [ 90, 90, 6A, 18, 68, A0, 24, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesIncrementalHandleReset + 146 77ED3440 11 Bytes [ 06, 53, FF, 75, 0C, 56, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesIncrementalHandleReset + 152 77ED344C 20 Bytes [ 06, 56, FF, 50, 08, EB, 3B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode + B 77ED35DA 8 Bytes [ F0, FF, D7, EB, 0E, 7E, 0A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode + 14 77ED35E3 94 Bytes [ FF, 00, 00, 0D, 00, 00, 07, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode + 73 77ED3642 5 Bytes [ 75, EB, 83, C7, 04 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode + 79 77ED3648 142 Bytes [ D3, 85, F6, 74, 0B, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode + 108 77ED36D7 18 Bytes [ 68, 06, 00, 02, 00, 50, 53, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode2 + 39 77ED3939 33 Bytes [ EB, 77, FF, 75, C4, FF, 15, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode2 + 5B 77ED395B 43 Bytes [ 01, 8A, 08, 40, 3A, CB, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode2 + 87 77ED3987 17 Bytes [ 15, 90, 10, E7, 77, 3B, F3, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode2 + 9A 77ED399A 5 Bytes [ 00, 00, 81, CE, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesProcEncodeDecode2 + A0 77ED39A0 58 Bytes [ 07, 80, 8B, C6, 8B, 4D, FC, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeFree2 + 31 77ED3B8D 14 Bytes [ 55, 8B, EC, 51, 51, 53, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesTypeFree2 + 40 77ED3B9C 126 Bytes [ 45, F8, 50, BF, 06, 00, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeEncode + 37 77ED3C1B 114 Bytes [ 75, 08, FF, 75, F8, FF, 15, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeDecode + 8 77ED3C8E 13 Bytes [ 5A, 8D, 45, CC, 50, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeDecode + 16 77ED3C9C 6 Bytes [ 00, 68, 58, 4B, EB, 77 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeDecode + 1D 77ED3CA3 215 Bytes [ 75, D0, FF, 15, 8C, 10, E7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeDecode + F5 77ED3D7B 41 Bytes [ 75, A4, FF, D6, 68, F0, 4E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrMesSimpleTypeDecode + 11F 77ED3DA5 102 Bytes [ 8D, 45, A8, 50, 53, 6A, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesEncodeIncrementalHandleCreate + 27 77ED3E42 34 Bytes [ 15, 30, 11, E7, 77, 85, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesEncodeIncrementalHandleCreate + 4A 77ED3E65 36 Bytes [ FF, EB, 1E, 56, 8B, 35, 6C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesDecodeIncrementalHandleCreate + C 77ED3E8A 3 Bytes [ 9F, 31, FA ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesDecodeIncrementalHandleCreate + 10 77ED3E8E 40 Bytes [ C9, C3, 7B, 62, 35, 38, 36, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesDecodeIncrementalHandleCreate + 39 77ED3EB7 27 Bytes [ 90, 54, 79, 70, 65, 46, 61, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesDecodeIncrementalHandleCreate + 55 77ED3ED3 157 Bytes [ 00, A1, AC, B2, EF, 77, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesInqProcEncodingId + 2F 77ED3F71 42 Bytes [ FF, 50, 68, 34, 31, ED, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesInqProcEncodingId + 5A 77ED3F9C 6 Bytes [ 50, 56, 68, 06, 00, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesInqProcEncodingId + 61 77ED3FA3 30 Bytes [ 56, 68, C4, 4E, EB, 77, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesInqProcEncodingId + 80 77ED3FC2 39 Bytes [ 39, 37, 0F, 84, 35, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!MesInqProcEncodingId + A8 77ED3FEA 30 Bytes [ 04, 06, 33, DB, 3B, C3, 75, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializePartial + 2A 77ED42A2 16 Bytes [ 89, BD, CC, FE, FF, FF, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializePartial + 3B 77ED42B3 43 Bytes [ FF, FF, 15, 90, 10, E7, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializePartial + 67 77ED42DF 3 Bytes [ DB, 7C, 02 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializePartial + 6B 77ED42E3 61 Bytes [ D8, 8B, 4D, FC, 5F, 5E, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerInitializePartial + AA 77ED4322 30 Bytes [ 00, 0F, 85, AF, 00, 00, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNsSendReceive + D 77ED43E9 3 Bytes [ 55, 8B, EC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNsSendReceive + 11 77ED43ED 47 Bytes [ 45, 08, 8B, 48, 04, F6, C1, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNsSendReceive + 41 77ED441D 61 Bytes [ 48, 60, 56, 8B, 31, 57, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNsSendReceive + 80 77ED445C 34 Bytes [ 00, 02, C6, 01, 01, FF, 40, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrNsSendReceive + A3 77ED447F 19 Bytes [ 50, 14, 8B, 48, 04, 83, EA, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcUserFree + 31 77ED456A 2 Bytes [ 6A, 08 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcUserFree + 34 77ED456D 5 Bytes [ 89, 83, 20, 01, 00 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcUserFree + 77 77ED45B0 46 Bytes CALL 77E933A5 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcUserFree + A6 77ED45DF 3 Bytes [ 89, E5, FB ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcUserFree + AA 77ED45E3 11 Bytes [ 8B, 45, 0C, 8B, 5D, 10, 89, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsBufferSize + 2C 77ED4DE9 8 Bytes [ 0F, B6, 10, C1, E1, 04, 0B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsBufferSize + 35 77ED4DF2 18 Bytes [ B6, 50, 01, C1, E1, 04, 0B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsBufferSize + 48 77ED4E05 25 Bytes [ 08, 5F, 89, 8B, 20, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsBufferSize + 62 77ED4E1F 32 Bytes [ EC, 56, 8B, 75, 14, 57, 56, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsBufferSize + 83 77ED4E40 37 Bytes [ 06, FF, 75, 0C, C6, 80, E4, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerBufferSize + 2 77ED4EF7 21 Bytes [ 75, 0C, 8B, 06, 57, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerBufferSize + 18 77ED4F0D 40 Bytes [ 00, 01, 8B, 06, 57, 6A, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrContextHandleSize + 9 77ED4F36 147 Bytes [ C7, 5F, 5E, 5D, C2, 0C, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPartialIgnoreClientBufferSize + 7D 77ED4FCA 224 Bytes [ 01, 00, 00, 6A, 05, 59, F3, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPartialIgnoreClientBufferSize + 15E 77ED50AB 244 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionBufferSize + 9F 77ED51A0 93 Bytes [ 8B, FF, 55, 8B, EC, E8, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructBufferSize + 5A 77ED51FE 169 Bytes [ 6A, FF, FF, 75, 08, 50, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructBufferSize + 104 77ED52A8 52 Bytes [ 68, 25, 07, 00, 00, E8, DC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeFree + 9 77ED52DD 172 Bytes [ F8, 85, FF, 74, 3B, 8B, 35, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerFree + 1B 77ED538B 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerFree + 1F 77ED538F 71 Bytes [ FF, 55, 8B, EC, 56, 8B, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerFree + 67 77ED53D7 157 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionFree + 4 77ED5475 9 Bytes [ 76, 0C, 85, F6, 75, E3, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionFree + E 77ED547F 128 Bytes [ 87, B0, 00, 00, 00, 81, 38, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionFree + 8F 77ED5500 43 Bytes [ 89, 42, 04, 89, 01, 83, C0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionFree + BB 77ED552C 3 Bytes [ 77, 41, FA ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionFree + BF 77ED5530 3 Bytes [ 5D, C2, 08 ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeMarshall + 59 77ED5693 159 Bytes [ 00, 00, 80, 3E, 4C, 0F, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMarshall + 96 77ED5733 88 Bytes [ EC, 83, 3D, 4C, B6, EF, 77, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMarshall + EF 77ED578C 15 Bytes [ 0F, 8B, 00, 89, 01, 8D, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMarshall + FF 77ED579C 6 Bytes [ 5D, 0A, E8, 58, 81, FC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMarshall + 106 77ED57A3 23 Bytes [ 85, C0, 7C, 14, 66, 83, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMarshall + 11E 77ED57BB 129 Bytes [ 8B, 45, 10, C7, 00, 01, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientContextMarshall + 35 77ED583D 165 Bytes [ EC, 0C, 56, 8B, 35, 84, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPartialIgnoreClientMarshall + 5F 77ED58E3 22 Bytes [ C7, 5F, 5E, C9, C2, 04, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPartialIgnoreClientMarshall + 76 77ED58FA 61 Bytes [ A1, AC, B2, EF, 77, 53, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMarshall + 39 77ED5938 82 Bytes [ 89, 4D, 84, A3, 2C, BD, EF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMarshall + 8C 77ED598B 31 Bytes [ E4, 89, 85, 68, FF, FF, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMarshall + AC 77ED59AB 20 Bytes [ 90, 8B, 45, 90, 89, 85, 6C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMarshall + C1 77ED59C0 120 Bytes [ 03, 57, 66, 89, 7D, 94, 66, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMarshall + 13A 77ED5A39 19 Bytes [ 50, 57, 6A, 08, 57, 68, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionMarshall + 17 77ED5BB8 54 Bytes [ 65, FC, 00, 53, 56, 8B, 35, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionMarshall + 4E 77ED5BEF 93 Bytes [ F8, 8D, 45, F4, 50, E8, 04, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeUnmarshall + 7 77ED5C4D 20 Bytes [ FC, 83, 7D, FC, 00, 74, 09, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrTypeUnmarshall + 1C 77ED5C62 197 Bytes [ FB, 02, 74, 06, 53, E8, 22, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructUnmarshall + B8 77ED5D28 60 Bytes [ EC, 8B, 45, 10, 33, C9, 8A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructUnmarshall + F5 77ED5D65 38 Bytes [ C1, F7, D1, 23, C1, 89, 42, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructUnmarshall + 11C 77ED5D8C 4 Bytes [ C1, 8B, 4D, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructUnmarshall + 121 77ED5D91 9 Bytes [ 48, 08, 8B, 4D, 10, 89, 48, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructUnmarshall + 12B 77ED5D9B 57 Bytes [ 08, C7, 00, B4, 4D, ED, 77, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsUnmarshall + 7 77ED60FC 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsUnmarshall + D 77ED6102 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsUnmarshall + 10 77ED6105 219 Bytes [ EC, 8B, 55, 10, 53, 8A, 5A, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsUnmarshall + EC 77ED61E1 200 Bytes [ 83, C7, 04, 89, 46, 14, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsUnmarshall + 1B6 77ED62AB 41 Bytes [ 90, 4E, 44, 52, 5F, 50, 46, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerUnmarshall + 2F 77ED6350 29 Bytes [ 49, 1C, 75, 13, 0F, B7, D2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerUnmarshall + 4F 77ED6370 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientContextUnmarshall + 4 77ED6376 47 Bytes [ 45, 0C, 85, C0, 74, 06, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrClientContextUnmarshall + 34 77ED63A6 187 Bytes [ 39, 88, 45, F4, 8A, 41, 14, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionUnmarshall + 5 77ED6462 55 Bytes [ 5F, 89, 46, 1C, 5E, 5B, C9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionUnmarshall + 3D 77ED649A 58 Bytes [ 45, 0C, 0F, BE, 08, EB, 1D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionUnmarshall + 78 77ED64D5 69 Bytes [ 00, 68, E6, 06, 00, 00, E8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionUnmarshall + BE 77ED651B 67 Bytes [ 89, 45, E4, 8B, 75, 08, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrEncapsulatedUnionUnmarshall + 102 77ED655F 23 Bytes [ ED, FC, FF, 80, 7D, 99, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMemorySize + 2E 77ED65C3 14 Bytes [ FF, 00, 00, 00, 00, 8E, 55, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMemorySize + 3D 77ED65D2 65 Bytes [ FF, 55, 8B, EC, 57, 8B, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMemorySize + 7F 77ED6614 5 Bytes [ 46, 44, FF, 75, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMemorySize + 125 77ED66BA 75 Bytes [ 80, F9, B2, 74, 0B, 80, F9, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrXmitOrRepAsMemorySize + 171 77ED6706 47 Bytes [ A8, 01, 74, 28, 33, C0, 8A, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerMemorySize + D 77ED680E 27 Bytes [ 7D, 10, 00, 74, 10, 83, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerMemorySize + 29 77ED682A 30 Bytes [ 83, C0, 03, 83, E0, FC, 50, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerMemorySize + 49 77ED684A 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerMemorySize + 4D 77ED684E 2 Bytes [ EC, 56 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrInterfacePointerMemorySize + 50 77ED6851 44 Bytes [ 75, 08, 8B, 46, 04, 6A, 00, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrPointerMemorySize + 1B 77ED6A9C 79 Bytes [ 47, 02, 8A, 08, 80, F9, 22, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMemorySize + 1 77ED6AEC 2 Bytes [ 7D, 0C ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMemorySize + 4 77ED6AEF 2 Bytes [ 5D, 10 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMemorySize + 7 77ED6AF2 73 Bytes [ 45, 14, 89, 45, 94, 56, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMemorySize + 51 77ED6B3C 131 Bytes CALL 77EA54A9 C:\WINDOWS\system32\RPCRT4.dll (Remote Procedure Call Runtime/Microsoft Corporation)
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConformantVaryingStructMemorySize + D5 77ED6BC0 147 Bytes [ B6, 80, 34, 5C, ED, 77, FF, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalSimpleTypeConvert + 7C 77ED75A2 5 Bytes [ 7D, 0C, 0F, B7, 5F ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalSimpleTypeConvert + 83 77ED75A9 64 Bytes [ 5D, E0, 8B, 75, 08, 01, 5E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalSimpleTypeConvert + C4 77ED75EA 1 Byte [ 4E ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalSimpleTypeConvert + C6 77ED75EC 32 Bytes [ 8B, 46, 04, 3B, 46, 0C, 76, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrUserMarshalSimpleTypeConvert + E7 77ED760D 33 Bytes [ 46, 2C, 3B, C1, 74, 09, 8B, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert2 77ED771A 21 Bytes [ 90, 90, 90, 6A, 18, 68, F0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert2 + 16 77ED7730 45 Bytes [ C0, 03, 83, E0, FC, 89, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert2 + 44 77ED775E 170 Bytes [ 89, 46, 04, 3B, CF, 75, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert + 51 77ED7809 44 Bytes [ 08, 8B, 46, 04, 83, C0, 03, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert + 7E 77ED7836 8 Bytes [ 0C, FF, 75, 0C, 56, E8, DD, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert + 87 77ED783F 93 Bytes [ FF, 8B, 46, 18, 5E, 5D, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert + 10A 77ED78C2 49 Bytes [ FF, EB, E0, 6A, 00, 6A, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrConvert + 13C 77ED78F4 25 Bytes [ 46, 18, 47, 47, 0F, BF, 07, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrGetSimpleTypeMemorySize + 14 77ED86C8 67 Bytes [ 8B, FF, 55, 8B, EC, 80, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpSetRpcSsDefaults + 3E 77ED872C 143 Bytes [ FF, 00, 00, 83, F8, 10, 74, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpSetRpcSsDefaults + CE 77ED87BC 117 Bytes [ EC, 51, 57, 8B, 7D, 08, 8B, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrpSetRpcSsDefaults + 144 77ED8832 328 Bytes [ 46, 85, DB, 75, 11, 6A, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmClientAllocate + 24 77ED897B 33 Bytes [ 4D, 08, 8B, 51, 04, 03, C2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmClientFree + A 77ED899D 284 Bytes [ 8B, 75, 10, 3B, F2, 0F, 8E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsAllocate + 65 77ED8ABA 61 Bytes [ 75, 08, 83, BE, 88, 00, 00, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsAllocate + A3 77ED8AF8 13 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsAllocate + B1 77ED8B06 18 Bytes [ 75, 10, 33, C9, 8A, 48, 01, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsSetThreadHandle + 70 77ED8C33 23 Bytes [ FF, 5F, 5E, 5B, 5D, C2, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsSwapClientAllocFree + 1 77ED8C4B 28 Bytes [ 5E, 04, 57, 8B, 7D, 0C, 0F, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSsSwapClientAllocFree + 1E 77ED8C68 85 Bytes [ 45, 08, 33, C0, 80, 3F, 1D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmAllocate + 30 77ED8CBE 110 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmClientFree + 34 77ED8D2D 50 Bytes [ 45, FC, 53, 56, 89, 7E, 10, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmDisableAllocate + F 77ED8D60 43 Bytes [ 46, 04, 74, 08, 83, C0, 08, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmDisableAllocate + 3B 77ED8D8C 53 Bytes [ 7D, 0C, 0F, B6, 47, 01, 8D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmFree + 19 77ED8DC2 60 Bytes [ 75, 10, 8A, 4E, 30, FF, 75, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmGetThreadHandle 77ED8E01 63 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmGetThreadHandle + 40 77ED8E41 81 Bytes [ FC, 74, 73, 53, 57, 8B, 7D, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmSetClientAllocFree + 3B 77ED8EA4 3 Bytes [ 10, 8B, 45 ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmSetClientAllocFree + 3F 77ED8EA8 70 Bytes [ 57, 56, 89, 5E, 10, 89, 46, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmSetThreadHandle + 26 77ED8EEF 13 Bytes [ 7D, 0C, 8A, 57, 01, 8B, 9E, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmSetThreadHandle + 34 77ED8EFD 69 Bytes [ 46, 04, 89, 7D, F0, 47, 47, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmSwapClientAllocFree + 22 77ED8F43 161 Bytes [ 75, F0, 83, C0, 03, 83, E0, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmSetClientToOsf + 36 77ED8FE5 51 Bytes [ 0B, 8B, 4E, 04, 03, C8, F7, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmSetClientToOsf + 6B 77ED901A 78 Bytes [ 8B, 45, FC, 89, 03, 75, 33, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmSetClientToOsf + BA 77ED9069 117 Bytes [ 4D, FC, F7, D9, 1B, C9, 23, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrRpcSmSetClientToOsf + 130 77ED90DF 33 Bytes [ 57, 8B, 7D, 0C, 89, 45, F8, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!RpcSmEnableAllocate + F 77ED9101 219 Bytes [ 45, 0C, 75, 08, 57, E8, 8C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerUnmarshall + 6E 77ED91DD 14 Bytes CALL 36FCD756
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerUnmarshall + 7D 77ED91EC 14 Bytes [ 3D, 6A, 00, 83, C0, 03, 83, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerUnmarshall + 8C 77ED91FB 6 Bytes [ 46, 10, E8, 34, 3A, FA ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerUnmarshall + 93 77ED9202 21 Bytes [ 80, 7D, 10, 00, 75, 16, 85, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerUnmarshall + A9 77ED9218 1 Byte [ 4D ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerMarshall + 8 77ED95C1 39 Bytes [ 73, 08, 8D, 04, 36, 39, 45, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerMarshall + 30 77ED95E9 10 Bytes [ 4C, 8B, D6, 8B, 33, C1, E2, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerMarshall + 3B 77ED95F4 221 Bytes JMP 039388FB
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerMarshall + 119 77ED96D2 42 Bytes [ 45, 0C, 83, 38, 00, 74, 0C, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!NdrServerMarshall + 144 77ED96FD 147 Bytes [ 8B, 45, 0C, 8B, 0D, 94, B8, … ]
.text …
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcProxyNewConnection + 63 77EE3E86 59 Bytes [ EC, 83, 7D, 08, 00, 56, 57, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcProxyNewConnection + 9F 77EE3EC2 16 Bytes [ 90, 90, 90, 90, 90, 8B, FF, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcProxyNewConnection + B0 77EE3ED3 64 Bytes [ FF, 75, 08, 50, 68, 9D, 02, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcProxyNewConnection + F1 77EE3F14 58 Bytes [ 83, 7B, 30, 02, 0F, 85, D4, … ]
.text C:\WINDOWS\system32\wscntfy.exe[320] RPCRT4.dll!I_RpcProxyNewConnection + 12C 77EE3F4F 128 Bytes [ EC, FF, 15, 5C, 13, E7, 77, … ]
.text …

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[1652] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Files - GMER 1.0.14 —-

File E:\SL Cache\05f113c9-1b85-3265-adf3-fa74847480e5.dsf 42476 bytes

—- EOF - GMER 1.0.14 —-
Fresh DDS DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 15:06:07.81 on Mon 02/16/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.130 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe E:\SUPERAntiSpyware.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\Linksys\WUSB100\WUSB100.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\rundll32.exe E:\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Jennifer\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - No File BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [SUPERAntiSpyware] E:\SUPERAntiSpyware.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [WinampAgent] e:\winamp\winampa.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [nwiz] nwiz.exe /install mRun: [SoundMan] SOUNDMAN.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRunOnce: [Malwarebytes' Anti-Malware] e:\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\jennifer\startm~1\programs\startup\imvu.lnk - c:\documents and settings\jennifer\application data\imvuclient\IMVUClient.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Syncura Document Sharing Service.lnk.disabled StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb100\WUSB100.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\spybot~1\SDHelper.dll DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - E:\SASWINLO.dll AppInit_DLLs: mwhsnr.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - E:\SASSEH.DLL LSA: Authentication Packages = msv1_0 c:\windows\system32\cbXqPFVm ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\jennifer\applic~1\mozilla\firefox\profiles\s6y15soe.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q= FF - plugin: c:\documents and settings\jennifer\application data\mozilla\firefox\profiles\s6y15soe.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07051001.dll FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: e:\divx web player\divx\divx content uploader\npUpload.dll FF - plugin: e:\divx web player\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: e:\divx web player\divx\divx web player\npdivx32.dll ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;E:\sasdifsv.sys [2009-1-15 8944] R1 SASKUTIL;SASKUTIL;E:\SASKUTIL.SYS [2009-1-15 55024] R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s [?] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s [?] R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632] R3 SASENUM;SASENUM;E:\SASENUM.SYS [2009-1-15 7408] S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -n "postgresql" -d "c:\program files\postgresql\8.0-beta2-dev3\data\" –> c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe [?] S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2005-2-24 44544] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;e:\sisoftware sandra lite 2009.sp2\RpcAgentSrv.exe [2009-2-15 98488] S4 Aiangvcs;Aiangvcs;c:\windows\system32\perfmon.exe [2001-8-23 15872] =============== Created Last 30 ================ 2009-02-16 14:30 250 a——- c:\windows\gmer.ini 2009-02-16 04:35 129,024 a——- c:\windows\system32\rtsrvw.dll 2009-02-16 04:35 129,024 a——- c:\windows\system32\phnfoktd.dll 2009-02-16 02:27 –d—– c:\docume~1\jennifer\applic~1\SUPERAntiSpyware.com 2009-02-09 07:30 54,156 a—h— c:\windows\QTFont.qfn 2009-02-09 07:30 1,409 a——- c:\windows\QTFont.for 2009-02-07 16:06 206,793 a——- c:\windows\system32\nvapps.nvb 2009-02-03 18:41 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll 2009-02-03 18:41 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2009-02-03 18:41 267,776 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-02-03 18:41 63,488 -c—— c:\windows\system32\dllcache\icardie.dll 2009-02-03 18:41 13,824 -c—— c:\windows\system32\dllcache\ieudinit.exe 2009-02-03 18:41 383,488 -c—— c:\windows\system32\dllcache\ieapfltr.dll 2009-02-03 18:41 2,455,488 -c—— c:\windows\system32\dllcache\ieapfltr.dat 2009-02-03 18:41 991,232 -c—— c:\windows\system32\dllcache\ieframe.dll.mui 2009-02-03 18:41 6,066,176 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-02-03 18:41 633,632 -c—— c:\windows\system32\dllcache\iexplore.exe 2009-02-03 15:35 –d—– c:\program files\Linksys 2009-02-03 15:29 16,512 a——- c:\windows\system32\drivers\RAPIProtocol.sys 2009-02-03 15:29 21,361 a——- c:\windows\system32\drivers\AegisP.sys 2009-02-03 15:22 –d—– C:\Linksys Driver 2009-02-03 14:46 4,490,712 a——- C:\WindowsUpdateAgent20-x86.exe 2009-02-03 14:46 1,266,056 a——- C:\WindowsXP-KB927891.exe 2009-02-03 10:23 –d—– c:\program files\Realtek AC97 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-02-02 12:27 200,411 a——- c:\windows\system32\nvapps.xml 2009-02-02 12:27 –d—– c:\windows\nview 2009-02-02 10:46 453,152 a——- c:\windows\system32\nvudisp.exe 2009-02-02 10:46 18,725 a——- c:\windows\system32\nvdisp.nvu 2009-02-02 10:46 453,152 a——- c:\windows\system32\NVUNINST.EXE 2009-02-02 10:45 –d—– C:\NVIDIA 2009-02-02 10:42 552 a——- c:\windows\system32\d3d8caps.dat 2009-02-02 10:41 –d—– c:\program files\SystemRequirementsLab 2009-02-01 15:48 1,645,320 a——- c:\windows\system32\gdiplus.dll 2009-01-30 22:17 –d—– c:\windows\Logs 2009-01-30 15:49 –d—– c:\windows\system32\NtmsData 2009-01-30 03:31 23 a–sh— c:\windows\system32\feba1_g.dll 2009-01-30 03:31 23 a——- c:\windows\system32\cccfffec3_g.ocx 2009-01-30 03:31 –d—– c:\program files\RegSupreme 2009-01-30 02:31 –d—– c:\documents and settings\jennifer\Tracing 2009-01-30 02:30 –d—– c:\program files\Microsoft 2009-01-30 02:29 –d—– c:\program files\Windows Live SkyDrive 2009-01-30 02:21 –d—– c:\program files\common files\Windows Live 2009-01-29 17:29 –d—– c:\documents and settings\jennifer\.housecall6.6 2009-01-29 13:39 101,888 ac—— c:\windows\system32\dllcache\adpu160m.sys 2009-01-29 13:39 46,112 ac—— c:\windows\system32\dllcache\adptsf50.sys 2009-01-29 13:29 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll 2009-01-29 09:36 –d—– c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters 2009-01-29 09:35 –d—– c:\windows\system32\CatRoot_bak 2009-01-28 02:17 1,324 a——- c:\windows\system32\d3d9caps.dat 2009-01-28 01:58 0 a——- c:\windows\ativpsrm.bin ==================== Find3M ==================== 2009-02-11 10:19 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 a——- c:\windows\system32\drivers\mbam.sys 2008-12-09 15:43 388,608 a——- c:\windows\system32\CF24313.exe 2008-12-09 03:18 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-04 10:36 3,396 a–sh— c:\windows\system32\dllcache\winsvcmgmnt.dll 2008-12-02 22:37 49,480 a——- c:\windows\system32\sirenacm.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll 2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll 2006-08-14 22:28 24,096 ac—— c:\docume~1\jennifer\applic~1\GDIPFONTCACHEV1.DAT 2008-01-15 09:13 861 a–sh— c:\windows\system32\dllcache\aamonit.dll 2008-01-15 09:13 847,872 a–shr– c:\windows\system32\dllcache\libeay32.dll 2008-01-15 09:13 159,744 a–shr– c:\windows\system32\dllcache\ssleay32.dll 2008-01-15 09:13 64,000 a–shr– c:\windows\system32\dllcache\syschk32.dll 2008-01-15 09:13 488 a–shr– c:\windows\system32\dllcache\winsvcf.dll 2008-01-15 09:13 895 a–shr– c:\windows\system32\dllcache\winsvcn.dll 2007-07-31 17:42 55,296 ac-shr– c:\windows\system32\spool\drivers\raddrv.dll ============= FINISH: 15:07:07.45 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI