Results.log contents:
Rootkit scan 2015-11-14 15:25:33
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000066 ST2000DL rev.CC3C 1863.02GB
Running: tcdtsf8p.exe; Driver: C:\Users\uy67\AppData\Local\Temp\uwtiyfob.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3328] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000074d12ab1 5 bytes JMP 000000010021f182
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000074e38781 5 bytes JMP 00000001734d1000
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074f31401 2 bytes JMP 74e5b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074f31419 2 bytes JMP 74e5b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074f31431 2 bytes JMP 74ed8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074f3144a 2 bytes CALL 74e3489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074f314dd 2 bytes JMP 74ed8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074f314f5 2 bytes JMP 74ed89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074f3150d 2 bytes JMP 74ed8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074f31525 2 bytes JMP 74ed8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074f3153d 2 bytes JMP 74e4fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074f31555 2 bytes JMP 74e568ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074f3156d 2 bytes JMP 74ed8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074f31585 2 bytes JMP 74ed8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074f3159d 2 bytes JMP 74ed86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074f315b5 2 bytes JMP 74e4fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074f315cd 2 bytes JMP 74e5b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074f316b2 2 bytes JMP 74ed8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe[208] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074f316bd 2 bytes JMP 74ed8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000074e38781 5 bytes JMP 00000001734d1000
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074f31401 2 bytes JMP 74e5b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074f31419 2 bytes JMP 74e5b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074f31431 2 bytes JMP 74ed8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074f3144a 2 bytes CALL 74e3489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074f314dd 2 bytes JMP 74ed8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074f314f5 2 bytes JMP 74ed89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074f3150d 2 bytes JMP 74ed8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074f31525 2 bytes JMP 74ed8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074f3153d 2 bytes JMP 74e4fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074f31555 2 bytes JMP 74e568ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074f3156d 2 bytes JMP 74ed8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074f31585 2 bytes JMP 74ed8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074f3159d 2 bytes JMP 74ed86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074f315b5 2 bytes JMP 74e4fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074f315cd 2 bytes JMP 74e5b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074f316b2 2 bytes JMP 74ed8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe[3928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074f316bd 2 bytes JMP 74ed8671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074f31401 2 bytes JMP 74e5b21b C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074f31419 2 bytes JMP 74e5b346 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074f31431 2 bytes JMP 74ed8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074f3144a 2 bytes CALL 74e3489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074f314dd 2 bytes JMP 74ed8822 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074f314f5 2 bytes JMP 74ed89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074f3150d 2 bytes JMP 74ed8718 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074f31525 2 bytes JMP 74ed8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074f3153d 2 bytes JMP 74e4fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074f31555 2 bytes JMP 74e568ef C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074f3156d 2 bytes JMP 74ed8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074f31585 2 bytes JMP 74ed8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074f3159d 2 bytes JMP 74ed86dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074f315b5 2 bytes JMP 74e4fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074f315cd 2 bytes JMP 74e5b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074f316b2 2 bytes JMP 74ed8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\RunDll32.exe[3844] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074f316bd 2 bytes JMP 74ed8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074f31401 2 bytes JMP 74e5b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074f31419 2 bytes JMP 74e5b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074f31431 2 bytes JMP 74ed8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074f3144a 2 bytes CALL 74e3489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074f314dd 2 bytes JMP 74ed8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074f314f5 2 bytes JMP 74ed89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074f3150d 2 bytes JMP 74ed8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074f31525 2 bytes JMP 74ed8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074f3153d 2 bytes JMP 74e4fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074f31555 2 bytes JMP 74e568ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074f3156d 2 bytes JMP 74ed8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074f31585 2 bytes JMP 74ed8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074f3159d 2 bytes JMP 74ed86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074f315b5 2 bytes JMP 74e4fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074f315cd 2 bytes JMP 74e5b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074f316b2 2 bytes JMP 74ed8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[4572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074f316bd 2 bytes JMP 74ed8671 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074f31401 2 bytes JMP 74e5b21b C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074f31419 2 bytes JMP 74e5b346 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074f31431 2 bytes JMP 74ed8f29 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074f3144a 2 bytes CALL 74e3489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074f314dd 2 bytes JMP 74ed8822 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074f314f5 2 bytes JMP 74ed89f8 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074f3150d 2 bytes JMP 74ed8718 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074f31525 2 bytes JMP 74ed8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074f3153d 2 bytes JMP 74e4fca8 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074f31555 2 bytes JMP 74e568ef C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074f3156d 2 bytes JMP 74ed8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074f31585 2 bytes JMP 74ed8b42 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074f3159d 2 bytes JMP 74ed86dc C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074f315b5 2 bytes JMP 74e4fd41 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074f315cd 2 bytes JMP 74e5b2dc C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074f316b2 2 bytes JMP 74ed8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\tcdtsf8p.exe[252] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074f316bd 2 bytes JMP 74ed8671 C:\Windows\syswow64\kernel32.dll
---- Kernel IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedEnableErrorSource] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedSetErrorSourceInfo] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedDisableErrorSource] [f640277700176ffc] [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedGetInjectionCapabilities] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedInjectError] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedFinalizeErrorRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedBugCheckSystem] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedAttemptErrorRecovery] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedWriteErrorRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedFreeMemory] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedClearErrorRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedIsSystemWheaEnabled] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedInitialize] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedReadErrorRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedAllocateMemory] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedGetBootErrorPacket] [?]
IAT C:\Windows\system32\ntoskrnl.exe[PSHED.dll!PshedGetAllErrorSources] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalIsHyperThreadingEnabled] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalEnumerateProcessors] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalQueryMaximumProcessorCount] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalStartNextProcessor] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRegisterDynamicProcessor] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalStartDynamicProcessor] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalInitializeProcessor] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSendSoftwareInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalCalibratePerformanceCounter] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!KeStallExecutionProcessor] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalEnableInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRequestClockInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetProfileInterval] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalStartProfileInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalStopProfileInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalHandleNMI] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalPerformEndOfInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRequestSoftwareInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalHandleMcheck] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRequestIpi] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalDisableInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!KeFlushWriteBuffer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetInterruptTargetInformation] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalInitializeOnResume] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalProcessorIdle] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalAllocateCrashDumpRegisters] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetTimeIncrement] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetEnvironmentVariable] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetEnvironmentVariable] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetEnvironmentVariableEx] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetEnvironmentVariableEx] [fd03411774cb3b44] [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalEnumerateEnvironmentVariablesEx] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalQueryEnvironmentVariableInfoEx] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetRealTimeClock] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSetBusDataByOffset] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetBusDataByOffset] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalReturnToFirmware] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetProcessorIdByNtNumber] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalTranslateBusAddress] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetMessageRoutingInfo] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalGetVectorInput] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRegisterErrataCallbacks] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!KeQueryPerformanceCounter] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalRequestDeferredRecoveryServiceInterrupt] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalAllProcessorsStarted] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalInitSystem] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalQueryRealTimeClock] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalInitializeBios] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalReportResourceUsage] [?]
IAT C:\Windows\system32\ntoskrnl.exe[HAL.dll!HalSendNMI] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [?]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsAdvanceLogBase] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtTailAdvanceFailure] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsPrivGetBaseLogFileFromFileObjectPointer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtHandleLogFileFull] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnGreater] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsReserveAndAppendLogAligned] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtSetLogFileSize] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnDifference] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsRemoveLogContainer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsAddLogContainer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsCreateMarshallingArea] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnLess] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnContainer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsFlushToLsn] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnInvalid] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsGetLogFileInformation] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtDeregisterManagedClient] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsCloseLogFileObject] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtInstallPolicy] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsMgmtRegisterManagedClient] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsCreateLogFile] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!CLFS_LSN_INVALID] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsLsnEqual] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsReadLogRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsReadNextLogRecord] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsTerminateReadLog] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsWriteRestartArea] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsDeleteLogByPointer] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsDeleteMarshallingArea] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!CLFS_LSN_NULL] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsReserveAndAppendLog] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CLFS.SYS!ClfsReadRestartArea] [?]
IAT C:\Windows\system32\ntoskrnl.exe[CI.dll!CiInitialize] [?]
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memcpy] [e8c88b486824548b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!?terminate@@YAXXZ] [24448948fffffbc4]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__set_app_type] [740030247c834830]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_fmode] [408b3824448b483c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_commode] [448948c08bc8ff38]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__setusermatherr] [12ab015ff4024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_amsg_exit] [4c894848244c8d48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_initterm] [4c40244c8b482024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!exit] [483024448b4cc98b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_cexit] [ffc88b486024548b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_exit] [448b4800012c9b15]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_XcptFilter] [ccc358c483483024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__wgetmainargs] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memset] [44894420244c8944]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthoritySid] [78ec834808244c89]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLengthRequiredSid] [448d4c48244c8d4c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlFreeHeap] [485024548d484024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCopySid] [e800000088248c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlAllocateHeap] [24bc8348fffff16c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeSid] [ff44750000000080]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthorityCountSid] [2444c700012a2b15]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventWrite] [b9410000004020]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlImageNtHeader] [40244c8b48000030]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventRegister] [244c8b4838418b44]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlUnhandledExceptionFilter] [c88b4818518b4840]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventEnabled] [448948fffffaf3e8]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSetProcessIsCritical] [38247c83483824]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCaptureContext] [1cbe9c0330775]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLookupFunctionEntry] [8024848b480deb00]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlVirtualUnwind] [3824448948000000]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeCriticalSection] [8824848b48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalAlloc] [244489c0ff302444]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CloseHandle] [b70f5024448b4830]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalFree] [830f302444390240]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ExpandEnvironmentStringsW] [3024448b000000cb]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!WideCharToMultiByte] [244c8b4828c06b48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!FreeLibrary] [48c18b48c8034848]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetLastError] [480000008824842b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcAddress] [48c8034838244c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExA] [8b6024448948c18b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DelayLoadFailureHook] [4828c06b48302444]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!Sleep] [48c8034848244c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetUnhandledExceptionFilter] [28b841c18b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetModuleHandleW] [60244c8b48d08b48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!QueryPerformanceCounter] [448b00012d6215ff]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetTickCount] [8b4828c06b483024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetSystemTimeAsFileTime] [480c01448b48244c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!UnhandledExceptionFilter] [48c8034838244c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetCommandLineW] [4828c06b48302444]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetErrorMode] [1401448b48244c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExW] [88248c8b48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcessHeap] [8948c18b48c80348]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CreateActCtxW] [5824448b48682444]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ActivateActCtx] [8b4828c06b483024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegQueryValueExW] [441001448b48244c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpW] [2cee15ff58244c8b]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrlenW] [8bffffff18e90001]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DeactivateActCtx] [e083000000982484]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ReleaseActCtx] [448b482275c08508]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetProcessAffinityUpdateMode] [8b48c82b4838244c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegisterWaitForSingleObjectEx] [4c8b48d08bc08bc1]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegOpenKeyExW] [8bfffff1d9e83824]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpiW] [e083000000982484]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapSetInformation] [44c7485275c08510]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegDisablePredefinedCacheEx] [3345000000002024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegCloseKey] [a024848b4cc9]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LCMapStringW] [8b484024548b4800]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapFree] [fffff548e838244c]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIf] [448b4800000183e8]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUseProtseqEpW] [ccc328c483483024]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!I_RpcMapWin32Status] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtSetServerStackSize] [4c89481024548948]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerRegisterIf] [8b4838ec83480824]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtStopServerListening] [15ff04488b482444]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtWaitServerListen] [2424448900012dec]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerListen] [ff088b4824448b48]
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIfEx] [24448900012ddb15]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memcpy] [ff088b4824448b48]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!?terminate@@YAXXZ] [244489003cb17b15]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__set_app_type] [e0c1482024448b20]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_fmode] [894840244c8b4820]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_commode] [4c8b482424448b01]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__setusermatherr] [4c8b480103484024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_amsg_exit] [448b480189484024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_initterm] [ccc338c483484024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!exit] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_cexit] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_exit] [4c89481024548948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_XcptFilter] [8b4848ec83480824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__wgetmainargs] [50b70f5824448b48]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memset] [b70f5824448b4802]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthoritySid] [ad2d2024448b2024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLengthRequiredSid] [83202444890024d9]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlFreeHeap] [97e9057d0020247c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCopySid] [2024446348000000]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlAllocateHeap] [448b482824448948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeSid] [8b4818c06b482824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthorityCountSid] [480849b70f58244c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventWrite] [482824448948c103]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlImageNtHeader] [3cc06b482824448b]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventRegister] [49b70f58244c8b48]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlUnhandledExceptionFilter] [24448948c103480a]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventEnabled] [6b482824448b4828]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSetProcessIsCritical] [f58244c8b483cc0]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCaptureContext] [8948c103480c49b7]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLookupFunctionEntry] [ffffffffb8282444]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlVirtualUnwind] [eb02762824443948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeCriticalSection] [c1482824448b4831]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalAlloc] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CloseHandle] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalFree] [4c89481024548948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ExpandEnvironmentStringsW] [480824448b480824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!WideCharToMultiByte] [48098b4810244c8b]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!FreeLibrary] [c30824448b480889]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetLastError] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcAddress] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExA] [4c89481024548948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DelayLoadFailureHook] [8b4848ec83480824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!Sleep] [58244c8b48502444]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetUnhandledExceptionFilter] [5b72083948098b48]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetModuleHandleW] [fde6e820244c8d48]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!QueryPerformanceCounter] [485024448b48ffff]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetTickCount] [48098b4858244c8b]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetSystemTimeAsFileTime] [448948c12b48008b]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!UnhandledExceptionFilter] [e820244c8d482024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetCommandLineW] [2444110ff2c02a0f]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetErrorMode] [4de820244c8d4830]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExW] [516e8c88b000004]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcessHeap] [30244c100ff20000]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CreateActCtxW] [ebc1280fc8580ff2]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ActivateActCtx] [448b48fffffd8be8]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegQueryValueExW] [4850244c8b485824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpW] [4c8d482824448948]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrlenW] [8b000003d9e82824]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DeactivateActCtx] [ff2c02a0f48f2c0]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ReleaseActCtx] [244c8d4838244411]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetProcessAffinityUpdateMode] [100ff2000004bbe8]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegisterWaitForSingleObjectEx] [fc8580ff238244c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegOpenKeyExW] [198605570f66c128]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpiW] [ccc348c48348003c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapSetInformation] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegDisablePredefinedCacheEx] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegCloseKey] [548948182444894c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LCMapStringW] [4808244c89481024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapFree] [20244c8d4868ec83]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIf] [100ff200000080]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUseProtseqEpW] [ff2003cad3a15ff]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!I_RpcMapWin32Status] [44100ff240244411]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtSetServerStackSize] [189e05590ff24024]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerRegisterIf] [52f0f66c033003c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtStopServerListening] [ff21f72003c189c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtWaitServerListen] [f66003c1892055c]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerListen] [d73003c188a052f]
IAT C:\Windows\system32\svchost.exe[3804] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIfEx] [b948]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memcpy] [83485708245c8948]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!?terminate@@YAXXZ] [8b4868598b4820ec]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__set_app_type] [6841c748f9]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_fmode] [894800001a82e800]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_commode] [4830245c8b48685f]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__setusermatherr] [ccccccc35f20c483]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_amsg_exit] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_initterm] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!exit] [4828ec8348575340]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_cexit] [8b48f98b4810418b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_exit] [db8548000000d098]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_XcptFilter] [441f0f663d74]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__wgetmainargs] [c085d0ffcf8b4818]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memset] [db85481b8b480f74]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthoritySid] [c0854810438b48c3]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLengthRequiredSid] [85d0ffcf8b480d74]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlFreeHeap] [48000001bc850fc0]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCopySid] [e820247c894ccf8b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlAllocateHeap] [85f88b440000343c]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeSid] [480000019c850fc0]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthorityCountSid] [276b3058b104f8b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventWrite] [bf41157448413900]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlImageNtHeader] [4cc78b410000014d]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventRegister] [28c4834820247c8b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlUnhandledExceptionFilter] [6de1d8b48c35b5f]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventEnabled] [4840246c89480002]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSetProcessIsCritical] [2464894c48247489]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCaptureContext] [74894cf633ed3350]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLookupFunctionEntry] [1497258d4c5824]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlVirtualUnwind] [8d4c4474db854800]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeCriticalSection] [fe8348000000f0b7]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalAlloc] [84c748c563480f7d]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CloseHandle] [f0c7]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalFree] [206681d8b4800]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ExpandEnvironmentStringsW] [74db8548f633ed33]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!WideCharToMultiByte] [140b78d4c44]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!FreeLibrary] [8b48327d0afe8348]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetLastError] [626e8d78b48084b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcAddress] [8b481a74c0850000]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExA] [1874040878830843]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DelayLoadFailureHook] [c6ff48c5ff1e8949]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!Sleep] [2067894c08c68349]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetUnhandledExceptionFilter] [c875db85481b8b48]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetModuleHandleW] [c563480f7d0afd83]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!QueryPerformanceCounter] [140c784c748]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetTickCount] [d1d8b4800000000]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetSystemTimeAsFileTime] [5824748b4c000206]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!UnhandledExceptionFilter] [6c8b485024648b4c]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetCommandLineW] [7b83000016ea358d]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetErrorMode] [84b8b485a750040]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExW] [5b8e8d78b48]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcessHeap] [8438b484a74c085]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CreateActCtxW] [438b507406087883]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ActivateActCtx] [20433918438b0875]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegQueryValueExW] [438b287789483672]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpW] [c1000001a08f8b1d]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrlenW] [20430318432b1ee0]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DeactivateActCtx] [676c83b0474c985]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ReleaseActCtx] [8b48000001a08789]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetProcessAffinityUpdateMode] [8b480000000abf41]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegisterWaitForSingleObjectEx] [8b4cc78b41482474]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegOpenKeyExW] [5f28c4834820247c]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpiW] [ccccccccccccc35b]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapSetInformation] [120ec81485740]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegDisablePredefinedCacheEx] [8b48006879834800]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegCloseKey] [4b80e75f9]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LCMapStringW] [5f00000120c48148]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapFree] [2a5580d8d48c3]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIf] [3e7b8000001]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUseProtseqEpW] [5f00000120c48148]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!I_RpcMapWin32Status] [d2854870578b48c3]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtSetServerStackSize] [190bf833474]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerRegisterIf] [20244c8d482b7500]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtStopServerListening] [65e800000001b841]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtWaitServerListen] [41104b8b4800007a]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerListen] [d08b4800000020b8]
IAT C:\Windows\system32\svchost.exe[4028] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIfEx] [c0850002ab4215ff]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memcpy] [4c894848244c8d48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!?terminate@@YAXXZ] [4c40244c8b482024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__set_app_type] [483024448b4cc98b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_fmode] [ffc88b486024548b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_commode] [448b4800015ceb15]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__setusermatherr] [ccc358c483483024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_amsg_exit] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_initterm] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!exit] [44894420244c8944]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_cexit] [4810245489481824]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_exit] [78ec834808244c89]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_XcptFilter] [448d4c48244c8d4c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__wgetmainargs] [e800000088248c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memset] [24bc8348fffff16c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthoritySid] [2444c700015a7b15]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLengthRequiredSid] [b9410000004020]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlFreeHeap] [40244c8b48000030]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCopySid] [244c8b4838418b44]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlAllocateHeap] [c88b4818518b4840]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeSid] [448948fffffaf3e8]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthorityCountSid] [38247c83483824]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventWrite] [1cbe9c0330775]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlImageNtHeader] [8024848b480deb00]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventRegister] [3824448948000000]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlUnhandledExceptionFilter] [8824848b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventEnabled] [c82b4840244c8b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSetProcessIsCritical] [50244c8b48c18b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCaptureContext] [4cc103481049b70f]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLookupFunctionEntry] [8824948b48c08b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlVirtualUnwind] [ff38244c8b480000]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeCriticalSection] [2444c700015e2b15]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalAlloc] [480000008824842b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CloseHandle] [48c8034838244c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalFree] [8b6024448948c18b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ExpandEnvironmentStringsW] [4828c06b48302444]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!WideCharToMultiByte] [48c8034848244c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!FreeLibrary] [28b841c18b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetLastError] [60244c8b48d08b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcAddress] [448b00015db215ff]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExA] [8b4828c06b483024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DelayLoadFailureHook] [480c01448b48244c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!Sleep] [48c8034838244c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetUnhandledExceptionFilter] [8b5824448948c18b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetModuleHandleW] [4828c06b48302444]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!QueryPerformanceCounter] [1401448b48244c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetTickCount] [88248c8b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetSystemTimeAsFileTime] [8948c18b48c80348]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!UnhandledExceptionFilter] [5824448b48682444]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetCommandLineW] [8b4828c06b483024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetErrorMode] [441001448b48244c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExW] [486824548b48c08b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcessHeap] [5d3e15ff58244c8b]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CreateActCtxW] [8bffffff18e90001]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ActivateActCtx] [448b482275c08508]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegQueryValueExW] [8b4818408b484024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpW] [4c8b48d08bc08bc1]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrlenW] [8bfffff1d9e83824]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DeactivateActCtx] [e083000000982484]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ReleaseActCtx] [44c7485275c08510]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetProcessAffinityUpdateMode] [a024848b4cc9]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegisterWaitForSingleObjectEx] [8b484024548b4800]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegOpenKeyExW] [fffff548e838244c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpiW] [24bc83482b75c085]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapSetInformation] [ff1c750000000080]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegDisablePredefinedCacheEx] [4c8b480001589315]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegCloseKey] [8b4838418b444024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LCMapStringW] [9de8c88b48382454]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapFree] [4805ebc033fffffb]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIf] [2424448900015e3c]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUseProtseqEpW] [ff088b4824448b48]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!I_RpcMapWin32Status] [24448900015e2b15]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtSetServerStackSize] [e0c1482024448b20]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerRegisterIf] [894840244c8b4820]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtStopServerListening] [4c8b482424448b01]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtWaitServerListen] [4c8b480103484024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerListen] [448b480189484024]
IAT C:\Windows\system32\svchost.exe[4072] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIfEx] [ccc338c483484024]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memcpy] [2a880c63024]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!?terminate@@YAXXZ] [80c63024448b4800]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__set_app_type] [448b4800000002a9]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_fmode] [4840244c8b483024]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_commode] [8b48000002b08889]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__setusermatherr] [30244c8b48382454]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_amsg_exit] [448b480000205be8]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_initterm] [ccc328c483483024]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!exit] [245488182444894c]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_cexit] [834808244c894810]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_exit] [e830244c8b4828ec]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!_XcptFilter] [24448b48fffffef4]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!__wgetmainargs] [3024448b48088948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[msvcrt.dll!memset] [24448b48000840c6]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthoritySid] [83483024448b4809]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLengthRequiredSid] [f4024448b4c10c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlFreeHeap] [e8c88b48382454b6]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCopySid] [24448b48fffffcb4]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlAllocateHeap] [ba000000d8054830]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeSid] [e8c88b4800004000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSubAuthorityCountSid] [24448b48fffffcfc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventWrite] [ba000001c0054830]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlImageNtHeader] [e8c88b4800004000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventRegister] [24448b48fffffdb4]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlUnhandledExceptionFilter] [ccccc328c4834830]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!EtwEventEnabled] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlSetProcessIsCritical] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlCaptureContext] [8d483024448b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlLookupFunctionEntry] [88948000281630d]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlVirtualUnwind] [33ee830244c8b48]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[ntdll.dll!RtlInitializeCriticalSection] [ccc328c483480000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalAlloc] [6e8c88b4810c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CloseHandle] [ccc328c483480000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LocalFree] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ExpandEnvironmentStringsW] [83483024448b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!WideCharToMultiByte] [c176e8c88b4828c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!FreeLibrary] [483024448b48ffff]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetLastError] [65e8c88b4808c083]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcAddress] [c328c48348ffffc1]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExA] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DelayLoadFailureHook] [4de830244c8b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!Sleep] [c328c48348ffffff]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetUnhandledExceptionFilter] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetModuleHandleW] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!QueryPerformanceCounter] [3de830244c8b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetTickCount] [c328c48348000000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetSystemTimeAsFileTime] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!UnhandledExceptionFilter] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetCommandLineW] [16e8c88b4828c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetErrorMode] [483024448b480000]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LoadLibraryExW] [95e8c88b4808c083]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!GetProcessHeap] [c328c48348ffffff]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!CreateActCtxW] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ActivateActCtx] [e8c88b48000000a0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegQueryValueExW] [28c48348ffffc0d4]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpW] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrlenW] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!DeactivateActCtx] [83483024448b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!ReleaseActCtx] [ffb6e8c88b4840c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!SetProcessAffinityUpdateMode] [95e8c88b4810c083]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegisterWaitForSingleObjectEx] [c328c48348ffffc0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegOpenKeyExW] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!lstrcmpiW] [88b3024448b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapSetInformation] [8348000504f215ff]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegDisablePredefinedCacheEx] [ccccccccccc328c4]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!RegCloseKey] [ec834808244c8948]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!LCMapStringW] [5483024448b4828]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[KERNEL32.dll!HeapFree] [e8c88b48000001c0]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIf] [cccccccccccccccc]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUseProtseqEpW] [244c894810245489]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!I_RpcMapWin32Status] [4c8b4828ec834808]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtSetServerStackSize] [8bfffffdb9e83024]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerRegisterIf] [c08501e083382444]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtStopServerListening] [e830244c8b480a74]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcMgmtWaitServerListen] [24448b48fffff754]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerListen] [ccccc328c4834830]
IAT C:\Windows\system32\svchost.exe[2952] @ C:\Windows\system32\svchost.exe[RPCRT4.dll!RpcServerUnregisterIfEx] [cccccccccccccccc]
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3428:2896] 000007fefb9b2a7c
Thread C:\Windows\system32\svchost.exe [3804:3808] 00000000ff5a246c
Thread C:\Windows\system32\svchost.exe [4028:4032] 00000000ff5a246c
Thread C:\Windows\system32\svchost.exe [4072:4076] 00000000ff5a246c
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\98588a039dc4
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\98588a039dc4 (not active ControlSet)
---- EOF - GMER 2.1 ----