GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2009-05-21 14:26:45
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.12 ----
SSDT spvb.sys ZwCreateKey
SSDT spvb.sys ZwEnumerateKey
SSDT spvb.sys ZwEnumerateValueKey
SSDT spvb.sys ZwOpenKey
SSDT spvb.sys ZwQueryKey
SSDT spvb.sys ZwQueryValueKey
SSDT spvb.sys ZwSetValueKey
Code 89F0F6A8 ZwFlushInstructionCache
Code 00000000 pIofCallDriver
Code 89D19826 IofCallDriver
Code 89F4366E IofCompleteRequest
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 89D1982B
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 89F43673
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 3 Bytes JMP 89F0F6AC
PAGE ntoskrnl.exe!ZwFlushInstructionCache + 4 80587BFF 1 Byte [ 09 ]
.text USBPORT.SYS!DllUnload B85D48AC 5 Bytes JMP 8A3131D8
---- User code sections - GMER 1.0.12 ----
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67601 63001675 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67618 6300168C 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67650 630016C4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67666 630016DA 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossing + FFF67685 630016F9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + B 63004092 82 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 5E 630040E5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 69 630040F0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 78 630040FF 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCrackUrlW + 7E 63004105 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 2B 630059AF 38 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 52 630059D6 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 58 630059DC 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 82 63005A06 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoA + 8B 63005A0F 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 22 63005BAB 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 2E 63005BB7 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 37 63005BC0 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 40 63005BC9 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoExW + 49 63005BD2 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 12 63006057 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 37 6300607C 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 4C 63006091 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 66 630060AB 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheHeaderData + 71 630060B6 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 22 63006F3B 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 32 63006F4B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 3A 63006F53 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 5F 63006F78 40 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!GetUrlCacheEntryInfoW + 88 63006FA1 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 8 63006FF1 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 13 63006FFC 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 2B 63007014 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 37 63007020 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindCloseUrlCache + 4B 63007034 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + 17 63007846 137 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + A1 630078D0 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + AE 630078DD 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + BD 630078EC 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryA + C1 630078F0 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 15 63007E73 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 1D 63007E7B 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheContainerA + 3C 63007E9A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 1F 63007EBE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 27 63007EC6 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 46 63007EE5 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 4B 63007EEA 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheContainerA + 56 63007EF5 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 33 6300E890 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 52 6300E8AF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 5B 6300E8B8 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 64 6300E8C1 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CommitUrlCacheEntryW + 6D 6300E8CA 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 13 6300EF8C 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 37 6300EFB0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 43 6300EFBC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 48 6300EFC1 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!CreateUrlCacheContainerA + 56 6300EFCF 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 18 6300FBB5 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 25 6300FBC2 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 2E 6300FBCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 3B 6300FBD8 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryExA + 5D 6300FBFA 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 15 6300FC5A 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 17 6300FC5C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 25 6300FC6A 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 49 6300FC8E 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindFirstUrlCacheEntryA + 5D 6300FCA2 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + B 63010770 116 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 80 630107E5 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + 88 630107ED 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + C0 63010825 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlW + F6 6301085B 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + B 63012844 91 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 67 630128A0 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + 6C 630128A5 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A5 630128DE 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionA + A7 630128E0 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 13 63014810 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 2A 63014827 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 32 6301482F 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 41 6301483E 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionA + 4C 63014849 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + B 630151C4 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 29 630151E2 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 33 630151EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 3B 630151F4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetUnlockRequestFile + 48 63015201 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 1F 63017372 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 24 63017377 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 2C 6301737F 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 41 63017394 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoA + 5E 630173B1 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 1B 63018290 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 20 63018295 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 28 6301829D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 3F 630182B4 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersA + 5E 630182D3 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + B 630187C7 92 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 68 63018824 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 6D 63018829 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 77 63018833 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestA + 79 63018835 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 7 6301944D 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 24 6301946A 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 28 6301946E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + 38 6301947E 127 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectA + B8 630194FE 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 7 6301A931 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 1C 6301A946 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 27 6301A951 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 43 6301A96D 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCreateUrlA + 5A 6301A984 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 22 6301AAEA 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 3F 6301AB07 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 56 6301AB1E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 64 6301AB2C 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetLockRequestFile + 6F 6301AB37 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 29 6301ACC6 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 2E 6301ACCB 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 3B 6301ACD8 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 53 6301ACF0 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetReadFile + 74 6301AD11 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + B 6301F308 53 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 41 6301F33E 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 4F 6301F34C 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 5D 6301F35A 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryOptionW + 8A 6301F387 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 32 6301F514 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 55 6301F537 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 5C 6301F53E 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 65 6301F547 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConnectW + 92 6301F574 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 1F 6301F75D 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 28 6301F766 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 4A 6301F788 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 52 6301F790 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpSendRequestW + 5B 6301F799 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 4C 6301F8C7 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 58 6301F8D3 13 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 67 6301F8E2 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 82 6301F8FD 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpOpenRequestW + 8C 6301F907 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 1E 6301FB5C 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 30 6301FB6E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 37 6301FB75 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 3D 6301FB7B 27 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpQueryInfoW + 5B 6301FB99 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 1D 6301FECE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 23 6301FED4 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 28 6301FED9 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 32 6301FEE3 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetQueryDataAvailable + 4C 6301FEFD 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 1E 63020A7F 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 2A 63020A8B 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 42 63020AA3 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 4B 63020AAC 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCloseHandle + 51 63020AB2 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 19 63021307 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 21 6302130F 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 2D 6302131B 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 35 63021323 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetConfirmZoneCrossingW + 47 63021335 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + C 63021865 15 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 1C 63021875 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 33 6302188C 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 3D 63021896 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryStream + 46 6302189F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 9 63021917 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 10 6302191E 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 1F 6302192D 23 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 37 63021945 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!UnlockUrlCacheEntryFile + 43 63021951 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 1D 630219E9 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 28 630219F4 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 3B 63021A07 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 44 63021A10 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!ReadUrlCacheEntryStreamEx + 53 63021A1F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 16 63022324 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 1F 6302232D 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 2A 63022338 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 39 63022347 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetTimeFromSystemTime + 52 63022360 76 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 9 630224C3 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 10 630224CA 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 14 630224CE 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 1A 630224D4 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!SetUrlCacheEntryInfoA + 27 630224E1 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 5 630261F2 64 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 46 63026233 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 4F 6302623C 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 63 63026250 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedStateExW + 70 6302625D 36 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + A 63026425 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + C 63026427 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 18 63026433 84 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 6D 63026488 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetGetConnectedState + 73 6302648E 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + B 630266EA 75 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 58 63026737 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 61 63026740 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 6A 63026749 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetSetOptionW + 73 63026752 44 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 18 63026AF1 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryA + 1C 63026AF5 52 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 30 63026B2A 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 53 63026B4D 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 64 63026B5E 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 6A 63026B64 49 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!FindNextUrlCacheEntryExA + 9C 63026B96 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5A 6302830D 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 5C 6302830F 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 65 63028318 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 6E 63028321 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!HttpAddRequestHeadersW + 7A 6302832D 4 Bytes [ 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 1E 630285B4 2 Bytes [ 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 23 630285B9 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 36 630285CC 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 3F 630285D5 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetCombineUrlW + 49 630285DF 2 Bytes [ 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 27 630286AB 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 2D 630286B1 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 39 630286BD 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 45 630286C9 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetInitializeAutoProxyDll + 4C 630286D0 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 1A 6302B2EF 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 2D 6302B302 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 36 6302B30B 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 3B 6302B310 32 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenA + 5E 6302B333 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 3F 6302B96D 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 4E 6302B97C 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[1408] WININET.dll!InternetOpenW + 69 6302B997 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]