PDA

View Full Version : SpybotSD.exe won't start



TWISTED88
2009-05-21, 00:29
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:17:37 PM, on 5/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {389956FE-3A45-469C-B944-70308E06BAAC} (CVServerObject Object) - http://192.168.0.110/videocom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232978082707
O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://192.168.0.101/xplugLiteAL.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3029BEC-3007-44D2-B816-B3D95FD6B91B}: NameServer = 192.168.0.1
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 8022 bytes

Shaba
2009-05-21, 13:24
Hi TWISTED88

To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

TWISTED88
2009-05-21, 21:27
Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1
Advanced Vista Codec Package
AI RoboForm (All Users)
Apple Software Update
Avanquest update
Avira AntiVir Personal - Free Antivirus
BlackSite: Area 51
Brothers In Arms
Brothers in Arms: Hell's Highway
Call of Duty
Call of Duty(R) - World at War(TM)
Call of Duty(R) - World at War(TM) 1.1 Patch
Call of Duty(R) - World at War(TM) 1.2 Patch
Call of Duty(R) - World at War(TM) 1.3 Patch
Call of Duty(R) 2
Call of Duty(R) 4 - Modern Warfare(TM)
CDDRV_Installer
Change Folder Icons
Cheetah DVD Burner
Chinese Traditional Fonts Support For Adobe Reader 9
Cold War
Content Transfer
Critical Update for Windows Media Player 11 (KB959772)
CrossLoop 2.44
Crysis WARHEAD(R)
Crysis WARHEAD(R)
Dark Sector
DataPilot
DEVIL MAY CRY 4
erLT
ERUNT 1.1j
EVEREST Ultimate Edition v4.20
F.E.A.R. 2 Project Origin
Fallout 3
Far Cry
Frontlines: Fuel of War
GameShadow
gBurner
Google Gmail Notifier
Grand Theft Auto IV
GRAW Patch 1.35
GTA San Andreas
Hellforces
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hour of Victory
iDEN Carrier RSS
iDEN Phonebook Manager
InterVideo Home Theater
Java(TM) 6 Update 13
Kane and Lynch: Dead Men
KhalInstallWrapper
Legend of Zelda, The Ocarina of Time 1.10
Logitech Gaming Software
Logitech iTouch Software
Logitech SetPoint
Lost Planet Extreme Condition
Medal of Honor Airborne
Medal of Honor Allied Assault
Medal of Honor Allied Assault(tm) Spearhead
Medal of Honor Allied Assault(tm) Spearhead
Medal of Honor Allied Assault(tm) Spearhead Patch 2.15
Media Center 13
Media Manager for WALKMAN 1.2
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Windows XP Video Decoder Checkup Utility
Motorola Driver Installation
Motorola Phone Tools
myJAL Apollo Edition
NecroVisioN
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Performance
NVIDIA Performance
NVIDIA PhysX
NVIDIA System Monitor
NVIDIA System Monitor
NVIDIA System Update
NVIDIA System Update
OpenAL
PeerGuardian 2.0
PerformanceTest v6.1
PowerISO
Product Key Explorer 1.9.6
Quake 4(TM)
Quantum of Solace(TM)
QuickTime
RCT3 Soaked
Registry Mechanic 7.0
Resistor Color Coder v1
Riva FLV Encoder 2.0
Rockstar Games Social Club
RollerCoaster Tycoon® 3
Samsung A950 USB - Handset Manager V9.2
Samsung CLP-550 Series PCL 6
Samsung USB Driver (MCCI 4.24)
Security Task Manager 1.7e
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Setup Wizard
Soldier of Fortune II - Double Helix
Spybot - Search & Destroy
Steam
SWAT 4
Terrorist Takedown 2 (1.01)
The Chronicles of Riddick: Escape From Butcher Bay
The Godfather™ II
The Royal Marines Commando (1.0)
Tom Clancy's EndWar
Tomb Raider: Underworld 1.0
Unreal Tournament 3
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB969497)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB-IrDA Adapter
USBTrace V2.2.7
Video Fixer 3.23
Video Server S
ViewSonic Monitor Drivers
VLC media player 0.9.8a
Wanted: Weapons of Fate
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows PowerShell(TM) 1.0
Windows PowerShell(TM) 1.0 MUI pack
Windows XP Service Pack 3
Wings of Honour - Battles of the Red Baron
WinRAR archiver
X10 Hardware(TM)
Xyanide Resurrection

Shaba
2009-05-21, 21:32
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

uTorrent


I'd like you to read the this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Please run a new HijackThis log scan when finished and post the log back here.

TWISTED88
2009-05-21, 22:21
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:13 PM, on 5/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {389956FE-3A45-469C-B944-70308E06BAAC} (CVServerObject Object) - http://192.168.0.110/videocom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232978082707
O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://192.168.0.101/xplugLiteAL.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3029BEC-3007-44D2-B816-B3D95FD6B91B}: NameServer = 192.168.0.1
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 7664 bytes

Shaba
2009-05-21, 22:23
Download gmer.zip (http://gmer.net/gmer.zip) and save to your desktop.
alternate download site (http://hype.free.googlepages.com/gmer.zip)

Unzip/extract the file to its own folder. (Click here (http://www.bleepingcomputer.com/tutorials/tutorial105.html) for information on how to do this if not sure. Win 2000 users click here (http://www.bleepingcomputer.com/tutorials/tutorial106.html).
When you have done this, disconnect from the Internet and close all running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double-click on Gmer.exe to start the program.
Allow the gmer.sys driver to load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
Click on the Rootkit tab.
Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
Click on the "Scan" and wait for the scan to finish.
Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
Note: If you have any problems, try running GMER in SAFE MODE (http://www.bleepingcomputer.com/forums/tutorial61.html)"
Important! Please do not select the "Show all" checkbox during the scan..

TWISTED88
2009-05-22, 00:37
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2009-05-21 14:26:45
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.12 ----

SSDT spvb.sys ZwCreateKey
SSDT spvb.sys ZwEnumerateKey
SSDT spvb.sys ZwEnumerateValueKey
SSDT spvb.sys ZwOpenKey
SSDT spvb.sys ZwQueryKey
SSDT spvb.sys ZwQueryValueKey
SSDT spvb.sys ZwSetValueKey

Code 89F0F6A8 ZwFlushInstructionCache
Code 00000000 pIofCallDriver
Code 89D19826 IofCallDriver
Code 89F4366E IofCompleteRequest

---- Kernel code sections - GMER 1.0.12 ----

.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 89D1982B
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 89F43673
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 3 Bytes JMP 89F0F6AC
PAGE ntoskrnl.exe!ZwFlushInstructionCache + 4 80587BFF 1 Byte [ 09 ]
.text USBPORT.SYS!DllUnload B85D48AC 5 Bytes JMP 8A3131D8

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67601 63001675 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67618 6300168C 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67650 630016C4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67666 630016DA 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67685 630016F9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + B 63004092 82 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 5E 630040E5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 69 630040F0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 78 630040FF 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 7E 63004105 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 2B 630059AF 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 52 630059D6 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 58 630059DC 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 82 63005A06 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 8B 63005A0F 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 22 63005BAB 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 2E 63005BB7 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 37 63005BC0 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 40 63005BC9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 49 63005BD2 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 12 63006057 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 37 6300607C 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 4C 63006091 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 66 630060AB 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 71 630060B6 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 22 63006F3B 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 32 63006F4B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 3A 63006F53 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 5F 63006F78 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 88 63006FA1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 8 63006FF1 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 13 63006FFC 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 2B 63007014 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 37 63007020 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 4B 63007034 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + 17 63007846 137 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + A1 630078D0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + AE 630078DD 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + BD 630078EC 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + C1 630078F0 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 15 63007E73 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 1D 63007E7B 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 3C 63007E9A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 1F 63007EBE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 27 63007EC6 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 46 63007EE5 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 4B 63007EEA 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 56 63007EF5 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 33 6300E890 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 52 6300E8AF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 5B 6300E8B8 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 64 6300E8C1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 6D 6300E8CA 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 13 6300EF8C 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 37 6300EFB0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 43 6300EFBC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 48 6300EFC1 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 56 6300EFCF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 18 6300FBB5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 25 6300FBC2 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 2E 6300FBCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 3B 6300FBD8 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 5D 6300FBFA 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 15 6300FC5A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 17 6300FC5C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 25 6300FC6A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 49 6300FC8E 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 5D 6300FCA2 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + B 63010770 116 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 80 630107E5 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 88 630107ED 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + C0 63010825 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + F6 6301085B 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + B 63012844 91 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 67 630128A0 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 6C 630128A5 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A5 630128DE 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A7 630128E0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 13 63014810 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 2A 63014827 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 32 6301482F 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 41 6301483E 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 4C 63014849 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + B 630151C4 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 29 630151E2 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 33 630151EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 3B 630151F4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 48 63015201 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 1F 63017372 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 24 63017377 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 2C 6301737F 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 41 63017394 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 5E 630173B1 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 1B 63018290 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 20 63018295 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 28 6301829D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 3F 630182B4 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 5E 630182D3 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + B 630187C7 92 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 68 63018824 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 6D 63018829 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 77 63018833 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 79 63018835 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 7 6301944D 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 24 6301946A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 28 6301946E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 38 6301947E 127 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + B8 630194FE 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 7 6301A931 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 1C 6301A946 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 27 6301A951 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 43 6301A96D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 5A 6301A984 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 22 6301AAEA 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 3F 6301AB07 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 56 6301AB1E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 64 6301AB2C 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 6F 6301AB37 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 29 6301ACC6 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 2E 6301ACCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 3B 6301ACD8 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 53 6301ACF0 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 74 6301AD11 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + B 6301F308 53 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 41 6301F33E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 4F 6301F34C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 5D 6301F35A 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 8A 6301F387 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 32 6301F514 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 55 6301F537 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 5C 6301F53E 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 65 6301F547 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 92 6301F574 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 1F 6301F75D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 28 6301F766 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 4A 6301F788 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 52 6301F790 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 5B 6301F799 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 4C 6301F8C7 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 58 6301F8D3 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 67 6301F8E2 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 82 6301F8FD 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 8C 6301F907 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 1E 6301FB5C 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 30 6301FB6E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 37 6301FB75 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 3D 6301FB7B 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 5B 6301FB99 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 1D 6301FECE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 23 6301FED4 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 28 6301FED9 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 32 6301FEE3 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 4C 6301FEFD 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 1E 63020A7F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 2A 63020A8B 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 42 63020AA3 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 4B 63020AAC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 51 63020AB2 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 19 63021307 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 21 6302130F 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 2D 6302131B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 35 63021323 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 47 63021335 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + C 63021865 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 1C 63021875 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 33 6302188C 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 3D 63021896 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 46 6302189F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 9 63021917 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 10 6302191E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 1F 6302192D 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 37 63021945 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 43 63021951 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 1D 630219E9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 28 630219F4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 3B 63021A07 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 44 63021A10 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 53 63021A1F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 16 63022324 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 1F 6302232D 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 2A 63022338 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 39 63022347 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 52 63022360 76 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 9 630224C3 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 10 630224CA 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 14 630224CE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 1A 630224D4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 27 630224E1 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 5 630261F2 64 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 46 63026233 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 4F 6302623C 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 63 63026250 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 70 6302625D 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + A 63026425 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + C 63026427 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 18 63026433 84 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 6D 63026488 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 73 6302648E 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + B 630266EA 75 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 58 63026737 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 61 63026740 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 6A 63026749 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 73 63026752 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 18 63026AF1 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 1C 63026AF5 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 30 63026B2A 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 53 63026B4D 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 64 63026B5E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 6A 63026B64 49 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 9C 63026B96 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5A 6302830D 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5C 6302830F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 65 63028318 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 6E 63028321 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 7A 6302832D 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 1E 630285B4 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 23 630285B9 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 36 630285CC 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 3F 630285D5 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 49 630285DF 2 Bytes [ 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 27 630286AB 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 2D 630286B1 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 39 630286BD 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 45 630286C9 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 4C 630286D0 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 1A 6302B2EF 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 2D 6302B302 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 36 6302B30B 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 3B 6302B310 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 5E 6302B333 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 3F 6302B96D 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 4E 6302B97C 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 69 6302B997 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]

TWISTED88
2009-05-22, 00:37
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 73 6302B9A1 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 83 6302B9B1 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 7 6302BAF4 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 12 6302BAFF 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 16 6302BB03 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 39 6302BB26 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 42 6302BB2F 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 1E 6302DF0E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 24 6302DF14 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 2E 6302DF1E 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 45 6302DF35 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 51 6302DF41 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 9 6302E82B 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 21 6302E843 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 25 6302E847 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 34 6302E856 47 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 64 6302E886 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 7 63030A6A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 9 63030A6C 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 20 63030A83 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 35 63030A98 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 45 63030AA8 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStream + 22 630326B1 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStream + 2E 630326BD 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 22 630326E4 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 2D 630326EF 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 3A 630326FC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 43 63032705 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 50 63032712 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 2D 63033454 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 36 6303345D 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 57 6303347E 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 68 6303348F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 74 6303349B 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 14 6303353A 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 2F 63033555 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 38 6303355E 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 44 6303356A 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 64 6303358A 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 23 630337A1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 2C 630337AA 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 33 630337B1 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 23 630337D9 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 29 630337DF 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 2E 630337E4 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 38 630337EE 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 4F 63033805 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + 82 63033F86 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + A5 63033FA9 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + A7 63033FAB 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + CE 63033FD2 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + DC 63033FE0 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 22 63034F06 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 29 63034F0D 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 50 63034F34 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 5D 63034F41 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 71 63034F55 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + 52 63035037 81 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + A6 6303508B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + AF 63035094 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + B1 63035096 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + C2 630350A7 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + 27 63035468 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + 33 63035474 112 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + A4 630354E5 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + AA 630354EB 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + AC 630354ED 45 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 12 63036833 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 24 63036845 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 3D 6303685E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 44 63036865 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 59 6303687A 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 12 6303DD83 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 18 6303DD89 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 22 6303DD93 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 2E 6303DD9F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 37 6303DDA8 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 9 6303EB32 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 10 6303EB39 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 1D 6303EB46 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 2B 6303EB54 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 37 6303EB60 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + C 6303F38D 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 12 6303F393 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 28 6303F3A9 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 50 6303F3D1 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 73 6303F3F4 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 25 6304309E 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 2B 630430A4 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 39 630430B2 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 42 630430BB 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 4C 630430C5 2 Bytes [ 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 12 6304320E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 22 6304321E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 2A 63043226 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 33 6304322F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 3C 63043238 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 52 630447A3 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 69 630447BA 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 76 630447C7 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 78 630447C9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 83 630447D4 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 18 63045AF6 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 1E 63045AFC 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 2A 63045B08 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 41 63045B1F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 4F 63045B2D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 1D 630462DF 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 26 630462E8 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 33 630462F5 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 58 6304631A 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 69 6304632B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + C 63050C42 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 10 63050C46 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 14 63050C4A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 18 63050C4E 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 1C 63050C52 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 2E 63053365 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 39 63053370 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 46 6305337D 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 4F 63053386 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 74 630533AB 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + B 63054627 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 20 6305463C 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 23 6305463F 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 30 6305464C 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 43 6305465F 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 1A 630547A1 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 23 630547AA 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 48 630547CF 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 63 630547EA 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 65 630547EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 22 63054867 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 2D 63054872 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 36 6305487B 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 3F 63054884 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 64 630548A9 57 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 15 63054BD4 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 17 63054BD6 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 21 63054BE0 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 25 63054BE4 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 24 63054C0D 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 31 63054C1A 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 3A 63054C23 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 43 63054C2C 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 46 63054C2F 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 1E 63055106 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 2C 63055114 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 58 63055140 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 63 6305514B 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 75 6305515D 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 30 630551C1 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 37 630551C8 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 55 630551E6 103 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + BD 6305524E 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + DD 6305526E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 7 630701E1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + D 630701E7 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 45 6307021F 60 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 82 6307025C 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 8F 63070269 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 5 6307085C 58 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 41 63070898 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 50 630708A7 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 55 630708AC 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 6F 630708C6 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + B 63070D60 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 2B 63070D80 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 37 63070D8C 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 39 63070D8E 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 3E 63070D93 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 17 63070DDC 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 25 63070DEA 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 2F 63070DF4 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 3F 63070E04 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 50 63070E15 33 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 5 63070EC8 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 1D 63070EE0 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 56 63070F19 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 5B 63070F1E 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 61 63070F24 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + B 6307136C 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 24 63071385 85 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 7B 630713DC 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 85 630713E6 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 9D 630713FE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + B 63071427 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 2A 63071446 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 3D 63071459 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 49 63071465 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 60 6307147C 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 24 630716D7 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 2C 630716DF 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 60 63071713 73 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + AA 6307175D 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + C8 6307177B 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 1A 630717AE 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 2D 630717C1 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 42 630717D6 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 52 630717E6 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 54 630717E8 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + B 63073853 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 19 63073861 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 20 63073868 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 2B 63073873 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 45 6307388D 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + D 63075DFF 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 13 63075E05 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 1F 63075E11 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 29 63075E1B 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 2F 63075E21 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 1E 63075E74 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 23 63075E79 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 36 63075E8C 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 3C 63075E92 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 4E 63075EA4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 5 63075EBB 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 29 63075EDF 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 33 63075EE9 36 Bytes [ 00

TWISTED88
2009-05-22, 00:51
---- System - GMER 1.0.12 ----

SSDT spvb.sys ZwCreateKey
SSDT spvb.sys ZwEnumerateKey
SSDT spvb.sys ZwEnumerateValueKey
SSDT spvb.sys ZwOpenKey
SSDT spvb.sys ZwQueryKey
SSDT spvb.sys ZwQueryValueKey
SSDT spvb.sys ZwSetValueKey

Code 89F0F6A8 ZwFlushInstructionCache
Code 00000000 pIofCallDriver
Code 89D19826 IofCallDriver
Code 89F4366E IofCompleteRequest

---- Kernel code sections - GMER 1.0.12 ----

.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 89D1982B
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 89F43673
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 3 Bytes JMP 89F0F6AC
PAGE ntoskrnl.exe!ZwFlushInstructionCache + 4 80587BFF 1 Byte [ 09 ]
.text USBPORT.SYS!DllUnload B85D48AC 5 Bytes JMP 8A3131D8

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67601 63001675 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67618 6300168C 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67650 630016C4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67666 630016DA 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67685 630016F9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + B 63004092 82 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 5E 630040E5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 69 630040F0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 78 630040FF 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 7E 63004105 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 2B 630059AF 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 52 630059D6 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 58 630059DC 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 82 63005A06 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 8B 63005A0F 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 22 63005BAB 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 2E 63005BB7 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 37 63005BC0 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 40 63005BC9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 49 63005BD2 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 12 63006057 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 37 6300607C 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 4C 63006091 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 66 630060AB 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 71 630060B6 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 22 63006F3B 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 32 63006F4B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 3A 63006F53 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 5F 63006F78 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 88 63006FA1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 8 63006FF1 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 13 63006FFC 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 2B 63007014 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 37 63007020 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 4B 63007034 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + 17 63007846 137 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + A1 630078D0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + AE 630078DD 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + BD 630078EC 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + C1 630078F0 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 15 63007E73 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 1D 63007E7B 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 3C 63007E9A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 1F 63007EBE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 27 63007EC6 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 46 63007EE5 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 4B 63007EEA 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 56 63007EF5 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 33 6300E890 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 52 6300E8AF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 5B 6300E8B8 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 64 6300E8C1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 6D 6300E8CA 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 13 6300EF8C 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 37 6300EFB0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 43 6300EFBC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 48 6300EFC1 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 56 6300EFCF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 18 6300FBB5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 25 6300FBC2 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 2E 6300FBCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 3B 6300FBD8 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 5D 6300FBFA 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 15 6300FC5A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 17 6300FC5C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 25 6300FC6A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 49 6300FC8E 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 5D 6300FCA2 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + B 63010770 116 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 80 630107E5 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 88 630107ED 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + C0 63010825 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + F6 6301085B 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + B 63012844 91 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 67 630128A0 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 6C 630128A5 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A5 630128DE 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A7 630128E0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 13 63014810 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 2A 63014827 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 32 6301482F 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 41 6301483E 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 4C 63014849 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + B 630151C4 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 29 630151E2 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 33 630151EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 3B 630151F4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 48 63015201 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 1F 63017372 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 24 63017377 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 2C 6301737F 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 41 63017394 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 5E 630173B1 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 1B 63018290 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 20 63018295 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 28 6301829D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 3F 630182B4 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 5E 630182D3 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + B 630187C7 92 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 68 63018824 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 6D 63018829 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 77 63018833 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 79 63018835 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 7 6301944D 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 24 6301946A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 28 6301946E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 38 6301947E 127 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + B8 630194FE 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 7 6301A931 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 1C 6301A946 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 27 6301A951 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 43 6301A96D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 5A 6301A984 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 22 6301AAEA 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 3F 6301AB07 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 56 6301AB1E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 64 6301AB2C 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 6F 6301AB37 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...

TWISTED88
2009-05-22, 00:51
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 29 6301ACC6 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 2E 6301ACCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 3B 6301ACD8 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 53 6301ACF0 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 74 6301AD11 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + B 6301F308 53 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 41 6301F33E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 4F 6301F34C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 5D 6301F35A 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 8A 6301F387 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 32 6301F514 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 55 6301F537 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 5C 6301F53E 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 65 6301F547 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 92 6301F574 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 1F 6301F75D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 28 6301F766 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 4A 6301F788 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 52 6301F790 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 5B 6301F799 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 4C 6301F8C7 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 58 6301F8D3 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 67 6301F8E2 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 82 6301F8FD 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 8C 6301F907 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 1E 6301FB5C 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 30 6301FB6E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 37 6301FB75 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 3D 6301FB7B 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 5B 6301FB99 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 1D 6301FECE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 23 6301FED4 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 28 6301FED9 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 32 6301FEE3 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 4C 6301FEFD 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 1E 63020A7F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 2A 63020A8B 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 42 63020AA3 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 4B 63020AAC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 51 63020AB2 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 19 63021307 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 21 6302130F 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 2D 6302131B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 35 63021323 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 47 63021335 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + C 63021865 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 1C 63021875 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 33 6302188C 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 3D 63021896 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 46 6302189F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 9 63021917 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 10 6302191E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 1F 6302192D 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 37 63021945 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 43 63021951 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 1D 630219E9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 28 630219F4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 3B 63021A07 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 44 63021A10 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 53 63021A1F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 16 63022324 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 1F 6302232D 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 2A 63022338 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 39 63022347 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 52 63022360 76 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 9 630224C3 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 10 630224CA 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 14 630224CE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 1A 630224D4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 27 630224E1 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 5 630261F2 64 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 46 63026233 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 4F 6302623C 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 63 63026250 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 70 6302625D 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + A 63026425 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + C 63026427 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 18 63026433 84 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 6D 63026488 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 73 6302648E 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + B 630266EA 75 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 58 63026737 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 61 63026740 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 6A 63026749 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 73 63026752 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 18 63026AF1 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 1C 63026AF5 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 30 63026B2A 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 53 63026B4D 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 64 63026B5E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 6A 63026B64 49 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 9C 63026B96 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5A 6302830D 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5C 6302830F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 65 63028318 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 6E 63028321 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 7A 6302832D 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 1E 630285B4 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 23 630285B9 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 36 630285CC 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 3F 630285D5 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 49 630285DF 2 Bytes [ 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 27 630286AB 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 2D 630286B1 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 39 630286BD 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 45 630286C9 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 4C 630286D0 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 1A 6302B2EF 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 2D 6302B302 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 36 6302B30B 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 3B 6302B310 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 5E 6302B333 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 3F 6302B96D 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 4E 6302B97C 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 69 6302B997 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 73 6302B9A1 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 83 6302B9B1 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 7 6302BAF4 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 12 6302BAFF 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 16 6302BB03 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 39 6302BB26 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallback + 42 6302BB2F 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 1E 6302DF0E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 24 6302DF14 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 2E 6302DF1E 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 45 6302DF35 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlA + 51 6302DF41 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 9 6302E82B 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 21 6302E843 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 25 6302E847 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 34 6302E856 47 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestA + 64 6302E886 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 7 63030A6A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 9 63030A6C 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 20 63030A83 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 35 63030A98 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlA + 45 63030AA8 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStream + 22 630326B1 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStream + 2E 630326BD 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 22 630326E4 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 2D 630326EF 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 3A 630326FC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 43 63032705 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamA + 50 63032712 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 2D 63033454 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 36 6303345D 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 57 6303347E 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 68 6303348F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExW + 74 6303349B 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 14 6303353A 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 2F 63033555 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 38 6303355E 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 44 6303356A 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieExA + 64 6303358A 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 23 630337A1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 2C 630337AA 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExW + 33 630337B1 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 23 630337D9 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 29 630337DF 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 2E 630337E4 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 38 630337EE 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFileExA + 4F 63033805 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + 82 63033F86 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + A5 63033FA9 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + A7 63033FAB 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + CE 63033FD2 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerW + DC 63033FE0 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 22 63034F06 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 29 63034F0D 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 50 63034F34 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 5D 63034F41 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryA + 71 63034F55 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + 52 63035037 81 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + A6 6303508B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + AF 63035094 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + B1 63035096 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieExW + C2 630350A7 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + 27 63035468 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + 33 63035474 112 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + A4 630354E5 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + AA 630354EB 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredW + AC 630354ED 45 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 12 63036833 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 24 63036845 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 3D 6303685E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 44 63036865 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IncrementUrlCacheHeaderData + 59 6303687A 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 12 6303DD83 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 18 6303DD89 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 22 6303DD93 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 2E 6303DD9F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacyGetZonePreferenceW + 37 6303DDA8 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 9 6303EB32 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 10 6303EB39 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 1D 6303EB46 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 2B 6303EB54 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntry + 37 6303EB60 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + C 6303F38D 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 12 6303F393 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 28 6303F3A9 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 50 6303F3D1 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsHostInProxyBypassList + 73 6303F3F4 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 25 6304309E 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 2B 630430A4 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 39 630430B2 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 42 630430BB 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlW + 4C 630430C5 2 Bytes [ 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 12 6304320E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 22 6304321E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 2A 63043226 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 33 6304322F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExA + 3C 63043238 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 52 630447A3 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 69 630447BA 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 76 630447C7 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 78 630447C9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroupW + 83 630447D4 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...

TWISTED88
2009-05-22, 00:52
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 18 63045AF6 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 1E 63045AFC 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 2A 63045B08 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 41 63045B1F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DetectAutoProxyUrl + 4F 63045B2D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 1D 630462DF 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 26 630462E8 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 33 630462F5 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 58 6304631A 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerW + 69 6304632B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + C 63050C42 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 10 63050C46 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 14 63050C4A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 18 63050C4E 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheEntryW + 1C 63050C52 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 2E 63053365 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 39 63053370 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 46 6305337D 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 4F 63053386 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryStreamW + 74 630533AB 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + B 63054627 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 20 6305463C 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 23 6305463F 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 30 6305464C 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateEx + 43 6305465F 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 1A 630547A1 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 23 630547AA 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 48 630547CF 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 63 630547EA 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFileW + 65 630547EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 22 63054867 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 2D 63054872 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 36 6305487B 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 3F 63054884 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileW + 64 630548A9 57 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 15 63054BD4 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 17 63054BD6 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 21 63054BE0 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryW + 25 63054BE4 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 24 63054C0D 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 31 63054C1A 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 3A 63054C23 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 43 63054C2C 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExW + 46 63054C2F 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 1E 63055106 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 2C 63055114 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 58 63055140 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 63 6305514B 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTimeW + 75 6305515D 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 30 630551C1 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 37 630551C8 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + 55 630551E6 103 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + BD 6305524E 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeToSystemTime + DD 6305526E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 7 630701E1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + D 630701E7 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 45 6307021F 60 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 82 6307025C 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFortezzaCommand + 8F 63070269 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 5 6307085C 58 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 41 63070898 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 50 630708A7 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 55 630708AC 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDialW + 6F 630708C6 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + B 63070D60 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 2B 63070D80 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 37 63070D8C 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 39 63070D8E 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetDial + 3E 63070D93 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 17 63070DDC 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 25 63070DEA 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 2F 63070DF4 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 3F 63070E04 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetHangUp + 50 63070E15 33 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 5 63070EC8 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 1D 63070EE0 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 56 63070F19 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 5B 63070F1E 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodial + 61 63070F24 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + B 6307136C 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 24 63071385 85 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 7B 630713DC 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 85 630713E6 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialHangup + 9D 630713FE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + B 63071427 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 2A 63071446 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 3D 63071459 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 49 63071465 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAutodialCallback + 60 6307147C 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 24 630716D7 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 2C 630716DF 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + 60 63071713 73 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + AA 6307175D 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnlineW + C8 6307177B 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 1A 630717AE 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 2D 630717C1 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 42 630717D6 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 52 630717E6 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGoOnline + 54 630717E8 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + B 63073853 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 19 63073861 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 20 63073868 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 2B 63073873 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DllInstall + 45 6307388D 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + D 63075DFF 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 13 63075E05 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 1F 63075E11 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 29 63075E1B 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCanonicalizeUrlA + 2F 63075E21 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 1E 63075E74 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 23 63075E79 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 36 63075E8C 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 3C 63075E92 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlA + 4E 63075EA4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 5 63075EBB 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 29 63075EDF 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 33 63075EE9 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 58 63075F0E 45 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCertByURL + 87 63075F3D 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetFilePointer + 20 63075F99 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetFilePointer + 25 63075F9E 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetFilePointer + 42 63075FBB 33 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetFilePointer + 65 63075FDE 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetFilePointer + 85 63075FFE 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoA + 13 6307606F 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoA + 3B 63076097 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoA + 49 630760A5 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoA + 67 630760C3 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoA + 80 630760DC 42 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAttemptConnect + 26 630761D2 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAttemptConnect + 28 630761D4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAttemptConnect + 3B 630761E7 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAttemptConnect + 4D 630761F9 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAttemptConnect + 6E 6307621A 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURL + C 630765C1 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURL + 10 630765C5 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURL + 21 630765D6 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURL + 2E 630765E3 48 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURL + 60 63076615 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFile + 1D 6307667B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFile + 27 63076685 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFile + 2C 6307668A 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFile + 3F 6307669D 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFile + 44 630766A2 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileA + 1D 630768AD 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileA + 27 630768B7 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileA + 2C 630768BC 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileA + 3C 630768CC 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileA + 41 630768D1 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURL + B 63076A7B 46 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURL + 3A 63076AAA 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURL + 40 63076AB0 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURL + 48 63076AB8 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURL + 6C 63076ADC 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionA + B 63076BD7 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionA + 39 63076C05 33 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionA + 5D 63076C29 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionA + 62 63076C2E 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionA + 7D 63076C49 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookupExW + 18 63077073 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookupExW + 2F 6307708A 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookupExW + 37 63077092 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookupExW + 3F 6307709A 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookup + 15 630770B4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookup + 22 630770C1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookup + 28 630770C7 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookup + 4F 630770EE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ForceNexusLookup + 57 630770F6 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateMD5SSOHash + B 630771E3 58 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateMD5SSOHash + 46 6307721E 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateMD5SSOHash + 54 6307722C 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateMD5SSOHash + 64 6307723C 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateMD5SSOHash + 6C 63077244 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlW + 8A 630773D1 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlW + 8C 630773D3 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlW + A8 630773EF 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenUrlW + B3 630773FA 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFileExA + 7 63077406 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetWriteFileExA + D 6307740C 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileW + B 6307741C 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileW + 1C 6307742D 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileW + 27 63077438 69 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileW + 6E 6307747F 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetFindNextFileW + 74 63077485 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionW + 44 63077515 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionW + 4C 6307751D 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionW + 4E 6307751F 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionW + 59 6307752A 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCheckConnectionW + 62 63077533 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetStatusCallbackW + 16 6307754E 62 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURLW + 3A 6307758D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURLW + 42 63077595 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURLW + 44 63077597 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURLW + 4F 630775A2 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetShowSecurityInfoByURLW + 58 630775AB 65 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURLW + 3D 630775ED 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURLW + 45 630775F5 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURLW + 47 630775F7 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURLW + 52 63077602 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetSecurityInfoByURLW + 5B 6307760B 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoW + 32 63077667 48 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoW + 63 63077698 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoW + 78 630776AD 56 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoW + B1 630776E6 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetLastResponseInfoW + BF 630776F4 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExA + 9 63077A17 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExA + 25 63077A33 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExA + 2C 63077A3A 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExW + 14 63077A53 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExW + 31 63077A70 42 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExW + 5C 63077A9B 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExW + 80 63077ABF 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionExW + 8A 63077AC9 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ResumeSuspendedDownload + 46 63079A9D 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ResumeSuspendedDownload + 4D 63079AA4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ResumeSuspendedDownload + 60 63079AB7 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ResumeSuspendedDownload + 6E 63079AC5 45 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ResumeSuspendedDownload + 9C 63079AF3 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...

TWISTED88
2009-05-22, 00:53
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DispatchAPICall + B 6307A298 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DispatchAPICall + 18 6307A2A5 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DispatchAPICall + 21 6307A2AE 65 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DispatchAPICall + 64 6307A2F1 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DispatchAPICall + 79 6307A306 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!_GetFileExtensionFromUrl + 13 6307BE4B 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!_GetFileExtensionFromUrl + 24 6307BE5C 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!_GetFileExtensionFromUrl + 2E 6307BE66 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!_GetFileExtensionFromUrl + 35 6307BE6D 42 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!_GetFileExtensionFromUrl + 60 6307BE98 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileA + 24 6307F1E4 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileA + 2C 6307F1EC 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileA + 37 6307F1F7 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileA + 3F 6307F1FF 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileA + 44 6307F204 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileA + 24 6307F2E3 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileA + 2C 6307F2EB 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileA + 37 6307F2F6 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileA + 40 6307F2FF 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileA + 4F 6307F30E 63 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileSize + 25 6308056A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileSize + 2A 6308056F 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileSize + 3B 63080580 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileSize + 40 63080585 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileSize + 67 630805AC 60 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileA + 7 630809BE 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileA + 16 630809CD 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileA + 7 630809D9 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileA + 19 630809EB 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryA + 7 630809F7 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryA + 16 63080A06 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryA + 7 63080A12 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryA + 16 63080A21 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryA + 7 63080A2D 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryA + 16 63080A3C 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryA + 38 63080A5E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryA + 3F 63080A65 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryA + 44 63080A6A 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandA + 7 63080BC4 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandA + 22 63080BDF 86 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandA + 7A 63080C37 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandA + 85 63080C42 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandA + 93 63080C50 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryA + 7 63081689 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryA + 19 6308169B 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryA + 2E 630816B0 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryA + 30 630816B2 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryA + 36 630816B8 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileA + 22 6308175A 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileA + 7 63081766 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileA + 9 63081768 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileA + 21 63081780 60 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileA + 5E 630817BD 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileA + 7C 630817DB 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileW + B 630819D8 68 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileW + 50 63081A1D 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileW + 59 63081A26 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileW + 5B 63081A28 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpFindFirstFileW + 73 63081A40 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileW + 2D 63081B29 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileW + 59 63081B55 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileW + 7D 63081B79 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileW + 98 63081B94 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpDeleteFileW + A1 63081B9D 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileW + 25 63081BD4 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileW + 2E 63081BDD 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileW + 33 63081BE2 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileW + 6A 63081C19 65 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRenameFileW + AC 63081C5B 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileW + 23 63081D10 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileW + 2C 63081D19 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileW + 2E 63081D1B 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileW + 39 63081D26 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpOpenFileW + 47 63081D34 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryW + 2D 63081DD4 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryW + 59 63081E00 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryW + 7D 63081E24 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryW + 98 63081E3F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCreateDirectoryW + A1 63081E48 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryW + 23 63081E7D 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryW + 2C 63081E86 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryW + 2E 63081E88 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryW + 39 63081E93 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpRemoveDirectoryW + 47 63081EA1 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryW + 23 63081F2E 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryW + 2C 63081F37 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryW + 2E 63081F39 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryW + 39 63081F44 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpSetCurrentDirectoryW + 47 63081F52 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryW + 2B 63081FE7 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryW + 3A 63081FF6 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryW + 3C 63081FF8 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryW + 44 63082000 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetCurrentDirectoryW + 58 63082014 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandW + 23 630820AE 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandW + 2C 630820B7 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandW + 2E 630820B9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandW + 39 630820C4 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpCommandW + 47 630820D2 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileW + 7 630827BE 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileW + 25 630827DC 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileW + 7 630827E8 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileW + 1F 63082800 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileEx + F 63082814 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileEx + 2F 63082834 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileEx + 3F 63082844 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileEx + 4E 63082853 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpGetFileEx + 64 63082869 45 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileEx + F 630828C6 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileEx + 2F 630828E6 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileEx + 3F 630828F6 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileEx + 4E 63082905 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FtpPutFileEx + 64 6308291B 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherCreateLocatorA + 7 63086858 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherCreateLocatorA + D 6308685E 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherFindFirstFileA + 7 6308686A 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherFindFirstFileA + D 63086870 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherOpenFileA + 7 6308687C 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherOpenFileA + D 63086882 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetLocatorTypeA + 7 6308688E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetLocatorTypeA + D 63086894 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetAttributeA + 7 630868A0 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetAttributeA + D 630868A6 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetAttributeA + 24 630868BD 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetAttributeA + 29 630868C2 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GopherGetAttributeA + 3B 630868D4 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteWpadCacheForNetworks + 26 63086B13 56 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteWpadCacheForNetworks + 5F 63086B4C 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteWpadCacheForNetworks + 7E 63086B6B 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteWpadCacheForNetworks + 88 63086B75 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteWpadCacheForNetworks + 97 63086B84 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacySetZonePreferenceW + B 6308A310 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacySetZonePreferenceW + 16 6308A31B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacySetZonePreferenceW + 1F 6308A324 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacySetZonePreferenceW + 25 6308A32A 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!PrivacySetZonePreferenceW + 2C 6308A331 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpCheckDavCompliance + 22 6308A623 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpCheckDavCompliance + 31 6308A632 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpCheckDavCompliance + 3A 6308A63B 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpCheckDavCompliance + 45 6308A646 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpCheckDavCompliance + 4E 6308A64F 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExA + 4A 6308AA38 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExA + 54 6308AA42 143 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExW + 8B 6308AAD2 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExW + 93 6308AADA 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExW + 95 6308AADC 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExW + A0 6308AAE7 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestExW + AA 6308AAF1 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestA + 25 6308AB1B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestA + 2D 6308AB23 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestW + 18 6308AB40 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestW + 20 6308AB48 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestW + 4B 6308AB73 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestW + 7F 6308ABA7 141 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpEndRequestW + 10E 6308AC36 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionA + 17 6308B160 77 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionA + 65 6308B1AE 72 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionW + 44 6308B1F7 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionW + 4C 6308B1FF 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionW + 4E 6308B201 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionW + 59 6308B20C 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetPerSiteCookieDecisionW + 62 6308B215 47 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionA + 2B 6308B245 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionA + 32 6308B24C 87 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionW + 53 6308B2A4 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionW + 55 6308B2A6 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionW + 60 6308B2B1 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetPerSiteCookieDecisionW + 6A 6308B2BB 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionA + 15 6308B2D5 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionA + 1B 6308B2DB 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionA + 41 6308B301 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionA + 4F 6308B30F 86 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionW + 52 6308B366 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionW + 62 6308B376 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionW + 6B 6308B37F 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionW + 79 6308B38D 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetEnumPerSiteCookieDecisionW + 8F 6308B3A3 107 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetClearAllPerSiteCookieDecisions + 67 6308B40F 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetClearAllPerSiteCookieDecisions + 7D 6308B425 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetClearAllPerSiteCookieDecisions + 8F 6308B437 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetClearAllPerSiteCookieDecisions + 91 6308B439 62 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetClearAllPerSiteCookieDecisions + D0 6308B478 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieA + 1C 6308C0E8 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieA + 7 6308C0F4 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieA + 9 6308C0F6 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieA + 26 6308C113 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieW + 7 6308C12F 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieW + 9 6308C131 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetCookieW + 1E 6308C146 152 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieW + 94 6308C1DF 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieW + 96 6308C1E1 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieW + BD 6308C208 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetCookieW + C7 6308C212 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTimeW + 24 6308C23B 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTimeW + 33 6308C24A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTimeW + 35 6308C24C 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTimeW + 3D 6308C254 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTimeW + 4D 6308C264 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UrlZonesDetach + 19 6308F177 63 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UrlZonesDetach + 59 6308F1B7 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UrlZonesDetach + 6E 6308F1CC 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UrlZonesDetach + 82 6308F1E0 59 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UrlZonesDetach + BF 6308F21D 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...

TWISTED88
2009-05-22, 00:53
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheGroup + B 63092D12 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheGroup + F 63092D16 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheGroup + 1C 63092D23 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheGroup + 2C 63092D33 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheGroup + 40 63092D47 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteIE3Cache + 6 63092D6C 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerA + 14 63092D85 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerA + 1E 63092D8F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerA + 26 63092D97 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerA + 32 63092DA3 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerA + 3F 63092DB0 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerW + B 63092DC0 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerW + F 63092DC4 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerW + 36 63092DEB 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerW + 40 63092DF5 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheContainerW + 48 63092DFD 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntryW + B 63092E35 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntryW + F 63092E39 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntryW + 13 63092E3D 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntryW + 41 63092E6B 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheEntryW + 57 63092E81 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheGroup + 9 63092EB1 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheGroup + 1F 63092EC7 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheGroup + 35 63092EDD 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheGroup + 41 63092EE9 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!DeleteUrlCacheGroup + 4E 63092EF6 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheGroup + A 63092F05 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheGroup + E 63092F09 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheGroup + 1E 63092F19 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheGroup + 2E 63092F29 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheGroup + 45 63092F40 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerW + B 63092F7C 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerW + F 63092F80 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerW + 1E 63092F8F 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerW + 41 63092FB2 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerW + 5B 63092FCC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheGroup + 9 63092FFC 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheGroup + 10 63093003 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheGroup + 20 63093013 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheGroup + 2D 63093020 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheGroup + 36 63093029 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExW + 3A 63093086 72 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExW + 84 630930D0 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExW + 94 630930E0 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExW + 96 630930E2 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExW + A1 630930ED 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceA + 14 63093115 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceA + 2A 6309312B 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceA + 36 63093137 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceA + 43 63093144 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceW + B 63093154 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceW + F 63093158 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceW + 13 6309315C 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceW + 3C 63093185 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FreeUrlCacheSpaceW + 52 6309319B 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoA + 16 630931DE 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoA + 29 630931F1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoA + 32 630931FA 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoA + 3F 63093207 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoA + 4C 63093214 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoW + B 63093224 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoW + 22 6309323B 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoW + 30 63093249 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoW + 47 63093260 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheConfigInfoW + 50 63093269 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeA + 9 630932A0 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeA + 1A 630932B1 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeA + 2E 630932C5 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeA + 47 630932DE 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeA + 56 630932ED 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeW + B 63093313 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeW + 2A 63093332 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeW + 3A 63093342 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeW + 57 6309335F 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheGroupAttributeW + 79 63093381 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredA + 24 63093401 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredA + 59 63093436 59 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredA + 95 63093472 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredA + 97 63093474 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!IsUrlCacheEntryExpiredA + B4 63093491 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!LoadUrlCacheContent + 7 6309349D 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileA + 9 630934AF 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileA + 17 630934BD 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileA + 1C 630934C2 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileA + 22 630934C8 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RetrieveUrlCacheEntryFileA + 32 630934D8 50 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RunOnceUrlCache + F 6309352C 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RunOnceUrlCache + 17 63093534 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RunOnceUrlCache + 1D 6309353A 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoW + B 6309354A 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoW + 2B 6309356A 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoW + 42 63093581 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoW + 4B 6309358A 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoW + 58 63093597 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroup + 9 630935B2 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroup + 18 630935C1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroup + 1E 630935C7 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroup + 24 630935CD 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryGroup + 34 630935DD 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoW + 41 6309365A 39 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoW + 69 63093682 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoW + 6B 63093684 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoW + 76 6309368F 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoW + 84 6309369D 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeA + 9 630936AB 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeA + 10 630936B2 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeA + 20 630936C2 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeA + 39 630936DB 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeA + 4A 630936EC 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeW + B 63093709 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeW + 21 6309371F 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeW + 3E 6309373C 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeW + 5B 63093759 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheGroupAttributeW + 6C 6309376A 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheHeaderData + 13 63093799 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheHeaderData + 18 6309379E 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheHeaderData + 1F 630937A5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheHeaderData + 2B 630937B1 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RegisterUrlCacheNotification + 14 630937CA 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RegisterUrlCacheNotification + 30 630937E6 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RegisterUrlCacheNotification + 3C 630937F2 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!RegisterUrlCacheNotification + 49 630937FF 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UpdateUrlCacheContentPath + 12 63093816 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UpdateUrlCacheContentPath + 1E 63093822 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UpdateUrlCacheContentPath + 45 63093849 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UpdateUrlCacheContentPath + 54 63093858 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UpdateUrlCacheContentPath + 60 63093864 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryW + 1C 63093926 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryW + 34 6309393E 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryW + 38 63093942 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryW + 46 63093950 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoA + B 63093960 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoA + 2A 6309397F 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoA + 2F 63093984 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoA + 43 63093998 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheConfigInfoA + 4C 630939A1 42 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowSecurityInfo + B 6309879F 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowSecurityInfo + 1A 630987AE 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowSecurityInfo + 28 630987BC 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowSecurityInfo + 34 630987C8 92 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowSecurityInfo + 91 63098825 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowCertificate + 7 63098946 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowCertificate + E 6309894D 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowClientAuthCerts + 7 63098959 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowClientAuthCerts + E 63098960 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ParseX509EncodedCertificateForListBoxEntry + 7 6309896C 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ParseX509EncodedCertificateForListBoxEntry + E 63098973 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowX509EncodedCertificate + 18 63098990 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowX509EncodedCertificate + 35 630989AD 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowX509EncodedCertificate + 40 630989B8 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowX509EncodedCertificate + 47 630989BF 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ShowX509EncodedCertificate + 53 630989CB 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringA + B 63098D3C 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringA + 2F 63098D60 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringA + 37 63098D68 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringA + 70 63098DA1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringA + 76 63098DA7 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringW + B 63098E9A 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringW + 2F 63098EBE 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringW + 37 63098EC6 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringW + 5D 63098EEC 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetAlgIdToStringW + 74 63098F03 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringA + 16 63099013 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringA + 25 63099022 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringA + 2D 6309902A 68 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringA + 72 6309906F 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringA + 7E 6309907B 62 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringW + B 630990E3 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringW + 19 630990F1 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringW + 28 63099100 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringW + 30 63099108 71 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSecurityProtocolToStringW + 78 63099150 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetErrorDlg + B 63099B8C 95 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetErrorDlg + 6B 63099BEC 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetErrorDlg + 77 63099BF8 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetErrorDlg + 7E 63099BFF 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetErrorDlg + 87 63099C08 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + 47 6309A0BB 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + 5D 6309A0D1 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + 6E 6309A0E2 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + 75 6309A0E9 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + 81 6309A0F5 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CollectCertPerformanceData + FFF82173 77A8153D 82 Bytes [ 12, A8, 77, 8B, F0, 89, 75, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CollectCertPerformanceData + FFF821C6 77A81590 1 Byte [ FF ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CollectCertPerformanceData + FFF821C8 77A81592 9 Bytes [ 3C, 12, A8, 77, FF, 35, 24, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CollectCertPerformanceData + FFF821D2 77A8159C 11 Bytes CALL FB1FBDB3
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CollectCertPerformanceData + FFF821DE 77A815A8 92 Bytes JMP 77A7EBC3
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptDetachTls + 42 77A8422C 18 Bytes CALL 77ADDF53 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptDetachTls + 55 77A8423F 8 Bytes [ FF, FF, EB, 12, 89, BD, 58, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptDetachTls + 5E 77A84248 467 Bytes [ FF, FF, 15, 8C, 11, A8, 77, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAllocTls + 49 77A8441D 85 Bytes [ BB, DC, 22, AB, 77, 53, C7, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInstallAsn1Module + 30 77A84473 94 Bytes CALL 77ABB8ED C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInstallAsn1Module + 8F 77A844D2 15 Bytes [ 50, 00, 72, 00, 6F, 00, 76, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInstallAsn1Module + 9F 77A844E2 678 Bytes [ 00, 00, 53, 6D, 61, 72, 74, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInstallAsn1Module + 346 77A84789 95 Bytes [ 00, 00, 00, C6, DD, A8, 77, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInstallAsn1Module + 3A6 77A847E9 144 Bytes [ 00, 00, 00, 63, 04, AE, 77, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgSignCTL + 12 77A84E74 16 Bytes [ FF, 85, C0, 0F, 84, 9E, 49, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgSignCTL + 23 77A84E85 44 Bytes [ 35, D0, 60, B0, 77, E8, D4, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgSignCTL + 50 77A84EB2 159 Bytes [ 00, 00, AE, 67, AC, 77, 03, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgSignCTL + F0 77A84F52 5 Bytes [ 00, 00, B1, 93, AC ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgSignCTL + F6 77A84F58 65 Bytes [ 17, 00, 00, 00, 9B, 95, AC, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetIntendedKeyUsage + 25 77A85773 307 Bytes [ 00, E2, 37, AD, 77, 48, 5F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetIntendedKeyUsage + 15A 77A858A8 145 Bytes [ 3C, 59, A8, 77, 4F, 58, A8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetIntendedKeyUsage + 1EC 77A8593A 101 Bytes [ 00, 00, 26, 43, AD, 77, 24, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetIntendedKeyUsage + 253 77A859A1 33 Bytes [ 56, 68, 44, 89, A8, 77, E8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetIntendedKeyUsage + 275 77A859C3 23 Bytes [ FF, 3B, C6, A3, 78, 64, B0, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInitOIDFunctionSet + 11 77A85F74 23 Bytes [ C3, F0, A9, 77, C3, F0, A9, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInitOIDFunctionSet + 29 77A85F8C 23 Bytes [ 4F, AC, AE, 77, C3, F0, A9, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInitOIDFunctionSet + 41 77A85FA4 43 Bytes [ D3, F1, A9, 77, CE, AF, AE, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInitOIDFunctionSet + 6D 77A85FD0 19 Bytes [ DA, A3, AE, 77, 61, A6, AE, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInitOIDFunctionSet + 81 77A85FE4 22 Bytes [ BD, B7, AE, 77, FB, BE, AE, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInstallOIDFunctionAddress + 21 77A86030 9 Bytes [ 08, 00, 00, 00, 08, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInstallOIDFunctionAddress + 2B 77A8603A 19 Bytes [ 00, 00, 10, 00, 00, 00, 50, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInstallOIDFunctionAddress + 41 77A86050 3 Bytes [ 08, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInstallOIDFunctionAddress + 45 77A86054 3 Bytes [ 08, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptInstallOIDFunctionAddress + 49 77A86058 17 Bytes [ 08, 00, 00, 00, 3C, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumSystemStoreLocation + 2B 77A86939 60 Bytes [ 00, 72, 00, 72, 00, 65, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumSystemStoreLocation + 68 77A86976 28 Bytes [ 33, 00, 32, 00, 5C, 00, 50, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumSystemStoreLocation + 85 77A86993 5 Bytes [ 00, 68, 80, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumSystemStoreLocation + 8B 77A86999 18 Bytes [ FF, 15, 78, 14, A8, 77, 3B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumSystemStoreLocation + 9E 77A869AC 99 Bytes [ 00, 89, 30, A1, D4, 60, B0, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptRegisterSmartCardStore + 23 77A86F34 117 Bytes [ FF, 55, 8B, EC, 51, 83, 65, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptRegisterSmartCardStore + 99 77A86FAA 15 Bytes [ 00, 74, 16, 3D, 00, 22, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptRegisterSmartCardStore + A9 77A86FBA 51 Bytes [ 24, 00, 00, 0F, 85, 69, 22, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptRegisterSmartCardStore + DD 77A86FEE 81 Bytes [ 90, 90, 90, 90, 90, 6A, 78, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptRegisterSmartCardStore + 12F 77A87040 33 Bytes [ 83, FA, FF, 0F, 84, E7, 4F, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetOIDFunctionAddress + 2 77A89972 1 Byte [ 56 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetOIDFunctionAddress + 4 77A89974 1 Byte [ F1 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetOIDFunctionAddress + 6 77A89976 29 Bytes [ 46, 18, 85, C0, 0F, 85, 93, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetOIDFunctionAddress + 24 77A89994 49 Bytes CALL 77A8925D C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetOIDFunctionAddress + 56 77A899C6 399 Bytes [ 00, 85, C0, 8B, 4D, 0C, 57, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptFreeOIDFunctionAddress + 7B 77A89B56 187 Bytes [ CB, 7A, FF, FF, FF, 15, AC, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 3F 77A89C12 47 Bytes [ 90, 90, 90, 90, 90, A1, 58, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 6F 77A89C42 8 Bytes [ 00, 00, 01, 00, 01, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 78 77A89C4B 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + AD 77A89C80 29 Bytes [ 6F, 00, 63, 00, 61, 00, 6C, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + CB 77A89C9E 79 Bytes [ 70, 00, 50, 00, 6F, 00, 6C, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryInfoKeyU + 3F 77A8A0E4 134 Bytes [ 31, 2E, 33, 2E, 36, 2E, 31, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryInfoKeyU + C6 77A8A16B 103 Bytes [ 2E, 31, 36, 00, 90, 31, 2E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryInfoKeyU + 12F 77A8A1D4 69 Bytes [ 31, 2E, 33, 2E, 36, 2E, 31, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenHKCUKeyExU 77A8A21C 69 Bytes [ 31, 2E, 33, 2E, 36, 2E, 31, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenKeyExU + 1C 77A8A264 118 Bytes [ 31, 2E, 33, 2E, 36, 2E, 31, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenKeyExU + 93 77A8A2DB 234 Bytes [ 90, 31, 2E, 33, 2E, 36, 2E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenKeyExU + 180 77A8A3C8 115 Bytes [ 31, 2E, 32, 2E, 38, 34, 30, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenKeyExU + 1F4 77A8A43C 110 Bytes [ 72, 00, 00, 00, 32, 2E, 35, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegOpenKeyExU + 263 77A8A4AB 2 Bytes [ 00, 44 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 27 77A8A53C 18 Bytes [ 43, 00, 00, 00, 45, 00, 6D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 3A 77A8A54F 4 Bytes [ 00, 4F, 00, 55 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 3F 77A8A554 7 Bytes [ 00, 00, 90, 90, 4F, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 47 77A8A55C 17 Bytes [ 4C, 00, 00, 00, 43, 00, 4E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 59 77A8A56E 7 Bytes [ 35, 00, 31, 00, 32, 00, 52 ]
.text ...

TWISTED88
2009-05-22, 00:54
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptEnumOIDFunction + B 77A8A814 2 Bytes [ 73, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptEnumOIDFunction + E 77A8A817 62 Bytes [ 00, 69, 00, 63, 00, 4B, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptEnumOIDFunction + 4D 77A8A856 5 Bytes [ 49, 00, 47, 00, 4E ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptEnumOIDFunction + 53 77A8A85C 7 Bytes [ 00, 00, 90, 90, 44, 00, 53 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptEnumOIDFunction + 5B 77A8A864 9 Bytes [ 53, 00, 00, 00, 52, 00, 53, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegEnumValueU + 2 77A8AEC6 38 Bytes CALL 77ACDD9C C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegEnumValueU + 29 77A8AEED 38 Bytes [ 00, FF, 36, 68, 54, 47, A8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegEnumValueU + 50 77A8AF14 24 Bytes CALL 77ACD2D2 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegEnumValueU + 69 77A8AF2D 5 Bytes [ 75, 14, FF, 75, 10 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegEnumValueU + 6F 77A8AF33 84 Bytes [ 75, 0C, FF, 75, 08, E8, A1, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptProtectData + 49 77A8B98B 88 Bytes CALL 77A8B93C C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptProtectData + A2 77A8B9E4 48 Bytes [ 00, 6A, 00, FF, 75, 14, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptProtectData + D4 77A8BA16 32 Bytes [ 14, 85, C0, 0F, 85, 3D, 6C, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptProtectData + F6 77A8BA38 35 Bytes [ F6, 46, 0A, 01, 75, 57, 33, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptProtectData + 11A 77A8BA5C 22 Bytes CALL 77A8F64E C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptUnprotectData + C 77A8BAFC 48 Bytes JMP 77A8BA57 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptUnprotectData + 3E 77A8BB2E 2 Bytes [ 27, 86 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptUnprotectData + 42 77A8BB32 16 Bytes [ F6, 45, 08, 04, 0F, 85, 5A, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptUnprotectData + 53 77A8BB43 51 Bytes [ 83, 7D, EC, 14, 0F, 85, CD, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptUnprotectData + 87 77A8BB77 118 Bytes [ DB, 6A, 0C, 8D, 45, E4, 50, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeLruCache + 6 77A8BE46 33 Bytes [ D8, FF, 85, C0, 74, AB, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeLruCache + 28 77A8BE68 32 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeLruCache + 49 77A8BE89 26 Bytes [ 5D, C2, 0C, 00, 8B, 45, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeLruCache + 64 77A8BEA4 19 Bytes [ 08, 50, 8D, 45, 0C, 50, 56, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeLruCache + 78 77A8BEB8 21 Bytes [ 4D, 0C, 03, C1, 3B, C6, 0F, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeTls + 9 77A8BF23 39 Bytes [ 8B, 55, 10, 89, 0A, 8B, 55, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeTls + 31 77A8BF4B 28 Bytes [ 7D, 10, 01, 72, 4D, 8B, 4D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeTls + 4E 77A8BF68 227 Bytes [ B6, C0, 3B, 45, 10, 73, 2E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeTls + 132 77A8C04C 36 Bytes [ 93, 00, 00, 00, 84, C9, 0F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFreeTls + 157 77A8C071 91 Bytes [ 3B, 45, 0C, 77, 7D, 8B, 55, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCloseStore + 2 77A8D6B0 34 Bytes [ 59, 59, 85, C0, 75, 07, 33, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCloseStore + 25 77A8D6D3 15 Bytes [ 56, 8B, 75, 0C, 57, 8B, FE, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCloseStore + 35 77A8D6E3 50 Bytes [ 89, 45, DC, 74, 06, 8D, 04, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCloseStore + 68 77A8D716 4 Bytes [ DE, 6B, DB, 38 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCloseStore + 6D 77A8D71B 23 Bytes [ FE, 6B, FF, 44, 8D, 04, F2, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetTls + 63 77A8DCBA 68 Bytes [ 85, C0, 89, 43, 34, 75, D6, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetTls + A9 77A8DD00 27 Bytes CALL 77A8C30D C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetTls + C5 77A8DD1C 43 Bytes [ 5E, BA, 01, 00, 83, 65, 18, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetTls + F1 77A8DD48 30 Bytes [ 0F, 85, 0D, 01, 00, 00, 53, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetTls + 110 77A8DD67 11 Bytes [ 45, D0, 50, 68, 8C, C9, A8, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindExtension + 10 77A8F9F6 65 Bytes [ 5F, 5E, 5B, C9, C2, 04, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindExtension + 53 77A8FA39 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindExtension + 57 77A8FA3D 35 Bytes [ FF, 55, 8B, EC, 51, 53, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindExtension + 7B 77A8FA61 8 Bytes [ F0, 3B, F7, 0F, 84, DD, 7F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindExtension + 84 77A8FA6A 23 Bytes CALL 77A825C6 C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddStoreToCollection + 36 77A8FC16 51 Bytes [ 35, 08, 64, B0, 77, E8, 70, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddStoreToCollection + 6B 77A8FC4B 1 Byte [ 18 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddStoreToCollection + 6D 77A8FC4D 10 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddStoreToCollection + 78 77A8FC58 59 Bytes [ EC, 58, A1, 30, 61, B0, 77, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddStoreToCollection + B4 77A8FC94 20 Bytes [ 85, 01, 86, 01, 00, 33, C0, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptFindOIDInfo + 83 77A90592 63 Bytes CALL 77A8D92B C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptFindOIDInfo + C3 77A905D2 91 Bytes CALL 77A818A7 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegCreateHKCUKeyExU + 36 77A9062E 37 Bytes [ 89, AB, CD, EF, C7, 40, 20, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegCreateHKCUKeyExU + 5C 77A90654 13 Bytes [ 40, 01, 00, 00, 8B, AC, 24, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegCreateHKCUKeyExU + 6A 77A90662 17 Bytes [ 8B, 5D, 04, 8B, 4D, 08, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegCreateHKCUKeyExU + 7C 77A90674 3 Bytes [ 00, 8B, 75 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegCreateHKCUKeyExU + 80 77A90678 146 Bytes [ 0F, CE, 89, 34, 24, 03, FE, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryValueExU + 60 77A9178B 21 Bytes [ 33, F5, 8B, AC, 24, 20, 01, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryValueExU + 76 77A917A1 35 Bytes [ C1, C5, 05, 8D, BC, 3D, D6, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryValueExU + 9B 77A917C6 140 Bytes [ 33, F5, 8B, AC, 24, 10, 01, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryValueExU + 128 77A91853 153 Bytes [ AC, 24, 2C, 01, 00, 00, 33, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!RegQueryValueExU + 1C2 77A918ED 46 Bytes [ 83, F9, 40, 0F, 82, D5, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCreateSelfSignCertificate + 18 77A919AA 3 Bytes [ 4D, 10, 8B ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCreateSelfSignCertificate + 1C 77A919AE 2 Bytes [ 08, C7 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCreateSelfSignCertificate + 1F 77A919B1 106 Bytes [ FC, 00, 00, 00, 00, 8B, 55, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCreateSelfSignCertificate + 8A 77A91A1C 14 Bytes CALL 77A905FC C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCreateSelfSignCertificate + 99 77A91A2B 26 Bytes [ 75, 10, 8D, 45, 88, 56, 50, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCRLContext + 15 77A91F74 43 Bytes [ FF, 85, C0, 75, C4, 33, C0, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCRLContext + 41 77A91FA0 99 Bytes [ 85, C0, 89, 45, FC, 0F, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObjectEx + 40 77A92004 8 Bytes [ FF, FF, 76, 0C, 57, 53, E8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObjectEx + 49 77A9200D 5 Bytes [ FF, FF, E9, 21, C1 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObjectEx + 4F 77A92013 25 Bytes [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObjectEx + 69 77A9202D 35 Bytes [ 48, 08, 38, 19, 0F, 84, 92, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObjectEx + 8D 77A92051 17 Bytes [ 75, 18, 8B, 45, 08, FF, 75, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertControlStore + F 77A920DE 48 Bytes [ 00, 56, 8B, 75, 10, 57, 33, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertControlStore + 40 77A9210F 202 Bytes [ 75, 0C, FF, D3, 85, C0, 0F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateStore + 67 77A921DB 29 Bytes [ 80, 39, 45, FC, 0F, 84, 51, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateStore + 85 77A921F9 3 Bytes [ 8F, 01, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateStore + 89 77A921FD 63 Bytes [ 45, FC, 50, FF, 75, 0C, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateStore + C9 77A9223D 97 Bytes [ 85, C0, 0F, 84, F0, D1, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateStore + 12B 77A9229F 14 Bytes [ FF, 75, 08, FF, 15, CC, 13, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashCertificate + 4B 77A92328 74 Bytes CALL 77A8B32B C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashCertificate + 96 77A92373 13 Bytes [ 03, 00, 00, 00, 33, C0, 40, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashCertificate + A4 77A92381 32 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashCertificate + C5 77A923A2 51 Bytes [ 57, FF, 15, 54, 12, A8, 77, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddSerializedElementToStore + 1 77A923D6 17 Bytes [ 44, 01, 30, 5D, C2, 04, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddSerializedElementToStore + 13 77A923E8 49 Bytes [ 00, 00, 00, 00, 42, 83, FA, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddSerializedElementToStore + 45 77A9241A 89 Bytes [ 8B, F8, 85, FF, 74, 40, 53, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddSerializedElementToStore + 9F 77A92474 30 Bytes [ FF, 55, 8B, EC, 56, 8B, 75, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertAddSerializedElementToStore + BE 77A92493 9 Bytes [ 5E, 5D, C2, 04, 00, 90, 90, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertDuplicateCRLContext + 16 77A92610 47 Bytes [ FF, BB, 00, 00, 01, 00, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOpenStore + 24 77A92640 9 Bytes [ FF, 8B, C6, 5E, 5B, 5F, 5D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOpenStore + 2E 77A9264A 16 Bytes [ 90, 90, 90, 90, 90, 90, 03, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOpenStore + 3F 77A9265B 43 Bytes [ 00, 39, 58, 14, 0F, 85, 75, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOpenStore + 6B 77A92687 98 Bytes [ 6A, 00, FF, 75, 14, FF, 75, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOpenStore + CE 77A926EA 145 Bytes [ BB, 20, C8, A8, 77, 53, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptImportPublicKeyInfoEx + 33 77A9277C 187 Bytes [ FF, 75, 14, FF, 75, 10, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptImportPublicKeyInfoEx + EF 77A92838 25 Bytes [ 3D, C8, 77, B0, 77, 00, 0F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptImportPublicKeyInfoEx + 109 77A92852 49 Bytes [ 5F, 5D, C2, 10, 00, 90, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptImportPublicKeyInfoEx + 13B 77A92884 53 Bytes CALL 77A93BD5 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptImportPublicKeyInfoEx + 171 77A928BA 30 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCRLContextProperty + 18 77A928FA 11 Bytes [ 8D, 4E, 08, 33, C0, E8, D4, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCRLContextProperty + 24 77A92906 8 Bytes [ 74, 2D, 83, C6, 1C, 56, 6A, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCRLContextProperty + 2D 77A9290F 154 Bytes [ 75, 0C, FF, 15, 8C, 13, A8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCRLContextProperty + C8 77A929AA 43 Bytes [ FF, 75, 0C, FF, 15, 0C, 14, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCRLContextProperty + F5 77A929D7 33 Bytes [ FF, 75, F8, FF, 75, 0C, FF, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetAsn1Decoder + F 77A92AA6 47 Bytes JMP 77A82621 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetAsn1Decoder + 3F 77A92AD6 57 Bytes [ 70, 08, FF, 70, 0C, 6A, 0E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetAsn1Decoder + 7A 77A92B11 16 Bytes [ 00, 74, 09, 83, 39, 00, 0F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetAsn1Decoder + 8B 77A92B22 5 Bytes [ 59, 8D, B8, A0, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetAsn1Decoder + 92 77A92B29 5 Bytes [ 8D, B2, A0, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgCountersignEncoded + 1 77A92CE9 211 Bytes [ EC, 51, 51, 56, 8B, F1, F6, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgCountersignEncoded + D5 77A92DBD 19 Bytes [ 8B, 40, 10, 89, 41, 10, EB, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgCountersignEncoded + E9 77A92DD1 74 Bytes [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgCountersignEncoded + 134 77A92E1C 8 Bytes [ EB, 25, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgCountersignEncoded + 13D 77A92E25 12 Bytes [ 55, 8B, EC, 51, 51, 53, 8B, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCertificateChain 77A92F67 49 Bytes [ 90, 8B, FF, 55, 8B, EC, 57, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCertificateChain + 32 77A92F99 30 Bytes [ 00, 00, 89, 77, 04, 5B, 5E, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCertificateChain + 51 77A92FB8 26 Bytes [ 15, 5C, 12, A8, 77, 85, C0, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCertificateChain + 6C 77A92FD3 10 Bytes CALL 77A941C8 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertGetCertificateChain + 80 77A92FE7 143 Bytes [ 56, 8B, 75, 08, 57, 8B, 7E, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOIDToAlgId + 1 77A93168 152 Bytes [ 45, FC, 74, 0C, 89, 45, F0, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOIDToAlgId + 9B 77A93202 53 Bytes [ 5D, C2, 08, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOIDToAlgId + D1 77A93238 9 Bytes [ F6, 43, 0D, 01, 0F, 85, 66, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOIDToAlgId + DB 77A93242 152 Bytes [ 57, 89, 75, 08, BF, 20, C8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertOIDToAlgId + 174 77A932DB 206 Bytes [ 3B, F7, 0F, 85, 2A, 47, 01, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObject 77A947AE 5 Bytes [ 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObject + 6 77A947B4 56 Bytes [ 55, 8B, EC, 56, 8B, 75, 0C, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObject + 40 77A947EE 40 Bytes [ 08, FF, B6, F4, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObject + 69 77A94817 2 Bytes [ 45, 08 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptDecodeObject + 6C 77A9481A 160 Bytes CALL 77A94828 C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareIntegerBlob + 18 77A94ACD 21 Bytes CALL 77A8170F C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareIntegerBlob + 2E 77A94AE3 111 Bytes [ 57, 50, 6A, 14, FF, 75, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificate + 18 77A94B53 44 Bytes [ 8D, 43, 50, 50, FF, 75, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificate + 45 77A94B80 33 Bytes CALL 77A82330 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificate + 67 77A94BA2 12 Bytes CALL 77A832F1 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificate + 74 77A94BAF 533 Bytes CALL 77A94BDD C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificate + 28A 77A94DC5 29 Bytes [ 57, 8B, D9, 89, 45, FC, 89, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertSetCRLContextProperty + A 77A95355 44 Bytes [ 0F, 84, 46, 80, 01, 00, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificateName + 1 77A95382 4 Bytes [ 06, 8B, 50, 0C ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificateName + 6 77A95387 45 Bytes [ 0B, 3B, CA, 0F, 86, D0, FE, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificateName + 35 77A953B6 64 Bytes [ 0C, 57, 33, FF, 3B, C7, 74, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificateName + 76 77A953F7 79 Bytes [ 4D, 08, 56, 57, 8B, 7D, 0C, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertCompareCertificateName + C6 77A95447 11 Bytes [ 01, 00, 8B, 75, FC, 8B, 4D, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAddRefLruEntry 77A955D7 31 Bytes [ 86, 01, 00, 80, 4E, 0F, 02, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAddRefLruEntry + 20 77A955F7 2 Bytes [ 45, 10 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAddRefLruEntry + 23 77A955FA 5 Bytes [ 40, 20, 8B, 58, 0C ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAddRefLruEntry + 29 77A95600 2 Bytes [ 47, 10 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptAddRefLruEntry + 2C 77A95603 75 Bytes [ 45, F8, 8B, 47, 14, 89, 45, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CertSyncStore + 19 77A95DE6 321 Bytes CALL 77A95E10 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CertSyncStore + 15B 77A95F28 8 Bytes [ 10, 06, 00, 00, 00, E8, B9, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CertSyncStore + 164 77A95F31 83 Bytes [ FF, 8B, 45, 0C, 85, 45, EC, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CertSyncStore + 1B8 77A95F85 8 Bytes [ 90, 90, 90, 14, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CertSyncStore + 1C1 77A95F8E 12 Bytes [ 00, 00, 20, 00, 00, 00, 90, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInStore + 16 77A96CBA 85 Bytes [ 08, 85, C0, 74, 0F, F6, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInStore + 6C 77A96D10 3 Bytes [ F6, 40, 08 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInStore + 70 77A96D14 49 Bytes [ 0F, 85, 31, EF, FF, FF, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInStore + A2 77A96D46 163 Bytes [ 65, F8, 00, 8B, F8, 33, C0, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInStore + 146 77A96DEA 71 Bytes [ 07, 00, 00, 00, EB, E7, 90, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReleaseLruEntry + 48 77A970F2 17 Bytes JMP 77A8E0E0 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReleaseLruEntry + 5A 77A97104 48 Bytes JMP 77A8E129 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReleaseLruEntry + 8B 77A97135 63 Bytes [ CC, C2, FF, FF, 50, 56, E8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReleaseLruEntry + CB 77A97175 149 Bytes [ 46, 14, 85, C0, 74, 09, 6A, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptReleaseLruEntry + 161 77A9720B 159 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInsertLruEntry + 1 77A973EF 28 Bytes [ 50, 20, 85, D2, 56, 0F, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInsertLruEntry + 1E 77A9740C 44 Bytes [ 40, 24, 89, 41, 04, 5D, C2, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInsertLruEntry + 4B 77A97439 24 Bytes [ EC, 53, 56, 57, 8B, 7D, 08, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInsertLruEntry + 64 77A97452 3 Bytes [ 6A, A0, FE ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptInsertLruEntry + 68 77A97456 110 Bytes CALL 77A814BE C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyRevocation + 36 77A97C44 28 Bytes [ 0F, F6, 43, 08, 08, 75, 09, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyRevocation + 53 77A97C61 138 Bytes CALL 77A977E9 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyRevocation + DE 77A97CEC 91 Bytes [ FF, 85, C0, 74, 71, 8B, 33, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyRevocation + 13A 77A97D48 27 Bytes CALL 77A97D68 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyRevocation + 156 77A97D64 10 Bytes [ EB, D1, 90, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyTimeValidity + 17 77A98245 88 Bytes [ 4D, F0, 50, 56, FF, 75, 08, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyTimeValidity + 70 77A9829E 23 Bytes [ DB, 89, 45, F0, 76, 05, 8B, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyTimeValidity + 88 77A982B6 9 Bytes CALL 77A9890C C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetLruEntryData + 2 77A982C0 12 Bytes CALL 989805C9
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetLruEntryData + F 77A982CD 47 Bytes [ 0F, 87, 28, F3, FF, FF, BB, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetLruEntryData + 3F 77A982FD 112 Bytes [ 75, 02, 0B, F2, 8B, 47, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetLruEntryData + B0 77A9836E 17 Bytes [ 01, BB, 00, 01, 00, 00, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptGetLruEntryData + C2 77A98380 67 Bytes [ 85, D0, 0F, 85, 4A, 4F, 01, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptVerifyCertificateSignatureEx + B 77A98CE7 94 Bytes CALL 77A8F6FC C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 6A 77A98D46 4 Bytes [ 40, C9, C2, 10 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 6F 77A98D4B 239 Bytes [ 90, 90, 90, 90, 90, 01, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 15F 77A98E3B 38 Bytes [ 83, 65, 10, 00, EB, A2, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 186 77A98E62 48 Bytes [ D2, 0F, 88, 1E, 0D, 01, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptCreateLruEntry + 32 77A99013 32 Bytes CALL 77A892D6 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptCreateLruEntry + 53 77A99034 39 Bytes CALL 77A814BE C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptCreateLruEntry + 7B 77A9905C 60 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptCreateLruEntry + B8 77A99099 58 Bytes [ B5, 74, FF, FF, FF, 56, E8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFindLruEntry + 25 77A990D5 9 Bytes [ 40, 10, 8B, 00, 8B, 40, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptFindLruEntry + 2F 77A990DF 60 Bytes [ 58, 04, 89, 5D, E0, 8B, 7D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 27 77A9911C 16 Bytes [ 90, 90, 90, 90, FF, FF, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 38 77A9912D 70 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 7F 77A99174 1 Byte [ 01 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 81 77A99176 6 Bytes [ C0, 74, 0A, 6A, 00, 6A ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 88 77A9917D 128 Bytes CALL 77A8925F C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumCTLsInStore + 1F 77A99490 22 Bytes [ 56, 8B, F1, 57, C1, E9, 02, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumCTLsInStore + 36 77A994A7 169 Bytes [ C2, 5D, C2, 04, 00, 90, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertEnumCTLsInStore + E0 77A99551 415 Bytes [ 75, 0C, 57, 8B, 7D, 08, 8D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCRLInStore + 7D 77A996F1 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCRLInStore + 80 77A996F4 43 Bytes [ EC, 56, 8B, 75, 0C, 57, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDDllList + C 77A99720 89 Bytes CALL 77A9A289 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDDllList + 66 77A9977A 17 Bytes [ 0F, 87, 65, 1E, 01, 00, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDDllList + 78 77A9978C 18 Bytes [ 55, 10, 89, 02, 8B, C1, 5D, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDDllList + 8B 77A9979F 90 Bytes [ EC, 8B, 45, 08, 8B, 00, 85, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDDllList + E6 77A997FA 9 Bytes [ 8B, 46, 48, 8B, 40, 08, FF, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 1C 77A9997D 110 Bytes [ 75, FC, FF, 15, 00, 14, A8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 8B 77A999EC 1 Byte [ 7D ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 8D 77A999EE 58 Bytes [ 8D, 4D, FC, 51, 50, 89, 07, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + C8 77A99A29 6 Bytes [ 83, 67, 08, 00, EB, E8 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + D2 77A99A33 20 Bytes [ 90, 8B, FF, 55, 8B, EC, 83, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInCRL + 3A 77A99C4E 13 Bytes [ C0, 74, 16, 33, C0, 39, 46, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInCRL + 48 77A99C5C 50 Bytes [ 00, 00, 0F, 85, A5, 1C, 01, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInCRL + 7C 77A99C90 39 Bytes [ 00, 5E, C9, C2, 08, 00, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInCRL + A4 77A99CB8 64 Bytes [ 3B, 00, 00, 00, 85, C0, 0F, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFindCertificateInCRL + E5 77A99CF9 86 Bytes [ 55, 8B, EC, 51, 51, 8B, 45, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgClose + 8 77A9A5E7 43 Bytes [ 45, FC, 8B, CE, 8B, 77, 04, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgClose + 34 77A9A613 6 Bytes [ FF, 75, F8, E8, F5, 29 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgClose + 3C 77A9A61B 61 Bytes [ 5F, 8B, C6, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgClose + 7A 77A9A659 38 Bytes [ 89, 01, EB, EF, 90, 90, 90, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptMsgClose + A1 77A9A680 74 Bytes [ 8B, 5D, 1C, 3B, DF, 8B, 75, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCertificateChain + 15 77A9B056 18 Bytes CALL 77A9A711 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCertificateChain + 28 77A9B069 13 Bytes [ FF, 75, FC, 6A, 29, FF, 75, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCertificateChain + 36 77A9B077 15 Bytes CALL 77A9D00E C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCertificateChain + 46 77A9B087 32 Bytes [ 8B, 45, 10, 83, C0, 48, 89, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertFreeCertificateChain + 67 77A9B0A8 61 Bytes [ 28, FF, FF, FF, 53, FF, 75, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertComparePublicKeyInfo + 17 77A9B599 154 Bytes CALL 77AE3E25 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertComparePublicKeyInfo + B2 77A9B634 2 Bytes [ FF, FF ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertComparePublicKeyInfo + B5 77A9B637 6 Bytes [ 24, 85, 96, E1, A9, 77 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertComparePublicKeyInfo + BC 77A9B63E 69 Bytes [ 75, 14, FF, 75, 0C, 53, E8, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertComparePublicKeyInfo + 102 77A9B684 66 Bytes CALL 77A8FEB6 C:\WINDOWS\system32\CRYPT32.dll
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyCertificateChainPolicy + 35 77A9B7A4 23 Bytes [ 18, 50, FF, 75, 10, FF, 73, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyCertificateChainPolicy + 4D 77A9B7BC 5 Bytes [ 45, FC, FF, 70, 70 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyCertificateChainPolicy + 53 77A9B7C2 27 Bytes CALL 778E2DC6
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyCertificateChainPolicy + 6F 77A9B7DE 11 Bytes [ 75, FC, 6A, 1B, FF, 75, E0, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CertVerifyCertificateChainPolicy + 7B 77A9B7EA 22 Bytes [ 83, 7D, F8, 00, 74, 09, FF, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashToBeSigned + 11 77A9B801 4 Bytes [ A8, 77, 74, 05 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashToBeSigned + 17 77A9B807 74 Bytes [ F4, FF, D7, 83, 7D, F0, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashToBeSigned + 62 77A9B852 18 Bytes CALL 77A9C475 C:\WINDOWS\system32\CRYPT32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashToBeSigned + 75 77A9B865 50 Bytes [ FF, 75, 0C, FF, 15, A0, 10, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] CRYPT32.dll!CryptHashToBeSigned + A8 77A9B898 39 Bytes CALL 77A99590 C:\WINDOWS\system32\CRYPT32.dll
.text ...

Shaba
2009-05-22, 07:14
Please try again and ensure that show all is not checked :)

Shaba
2009-05-27, 07:10
Due to the lack of feedback this Topic is closed.

If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

Everyone else please begin a New Topic.