Torna indietro   Hardware Upgrade Forum > Networking e sicurezza > Antivirus e Sicurezza > Tutorial / How-To / F.A.Q.

DJI Romo, il robot aspirapolvere tutto trasparente
DJI Romo, il robot aspirapolvere tutto trasparente
Anche DJI entra nel panorama delle aziende che propongono una soluzione per la pulizia di casa, facendo leva sulla propria esperienza legata alla mappatura degli ambienti e all'evitamento di ostacoli maturata nel mondo dei droni. Romo è un robot preciso ed efficace, dal design decisamente originale e unico ma che richiede per questo un costo d'acquisto molto elevato
DJI Osmo Nano: la piccola fotocamera alla prova sul campo
DJI Osmo Nano: la piccola fotocamera alla prova sul campo
La nuova fotocamera compatta DJI spicca per l'abbinamento ideale tra le dimensioni ridotte e la qualità d'immagine. Può essere installata in punti di ripresa difficilmente utilizzabili con le tipiche action camera, grazie ad una struttura modulare con modulo ripresa e base con schermo che possono essere scollegati tra di loro. Un prodotto ideale per chi fa riprese sportive, da avere sempre tra le mani
FUJIFILM X-T30 III, la nuova mirrorless compatta
FUJIFILM X-T30 III, la nuova mirrorless compatta
FUJIFILM X-T30 III è la nuvoa fotocamera mirrorless pensata per chi si avvicina alla fotografia e ricerca una soluzione leggera e compatta, da avere sempre a disposizione ma che non porti a rinunce quanto a controllo dell'immagine.
Tutti gli articoli Tutte le news

Vai al Forum
Rispondi
 
Strumenti
Old 30-03-2008, 21:16   #141
done75
Senior Member
 
L'Avatar di done75
 
Iscritto dal: Mar 2007
Messaggi: 2448
ragazzi,una domanda... se non ho nemmeno UNA voce in rosso dopo scansione, non dovrei avere rootkit,vero? insomma,quante probabilita ci sono che un rootkit non lasci neanche una traccia in rosso?
__________________
CASE: Aerocool CS-107 v2 | CPU: AMD Ryzen 7 5700x | MB: ASUS TUF Gaming B550M-Plus | GPU: SAPPHIRE Radeon RX 570 Pulse ITX 4GB | RAM: G.Skill RipjawsV DDR4 3200-C15 16GB | NMVE: Samsung 970 EVO M.2 250GB | SSD1: Crucial MX500 250GB | SSD2: Silicon Power A55 2TB | MAST.: LG GP57EB40 | FANS: 3x Thermalright TL-C12C | ALI: Be Quiet! Pure Power 11 CM500W | AUDIO: Audient iD4 MKII | 2.0 M-Audio BX8 D2 | OS1: EndeavourOS | OS2: Linux Mint 21.3 | OS3: Windows 11 Pro
done75 è offline   Rispondi citando il messaggio o parte di esso
Old 31-03-2008, 19:14   #142
Chill-Out
Moderatore
 
L'Avatar di Chill-Out
 
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
Quote:
ragazzi,una domanda... se non ho nemmeno UNA voce in rosso dopo scansione, non dovrei avere rootkit,vero?
esatto non dovresti avere Rootkit

Quote:
insomma,quante probabilita ci sono che un rootkit non lasci neanche una traccia in rosso?
teoricamente nessuna, il che vuol dire che se Gmer non rileva righe rosse non dovresti avere Rootkit attivi, considera che ho usato il condizionale, il fatto che Gmer non mostra righe rosse non esclude a priori che non ci sono Rootkit l'unica cosa certa e che lui non li rileva, quindi è sempre opportuno utilizzare più software alla ricerca di evenutali file hidden.

Link utili:
http://www.hwupgrade.it/forum/showth...hlight=ROOTKIT
http://www.hwupgrade.it/forum/showth...5BNEWS%5D+TEST
__________________
Try again and you will be luckier.

Ultima modifica di Chill-Out : 31-03-2008 alle 19:16.
Chill-Out è offline   Rispondi citando il messaggio o parte di esso
Old 06-04-2008, 02:44   #143
VdW
Senior Member
 
L'Avatar di VdW
 
Iscritto dal: Jun 2004
Messaggi: 2171
Ciao, vi posto il mio log, grazie della vostra disponibilita'

Codice:
GMER 1.0.14.14205 - http://www.gmer.net
Rootkit scan 2008-04-06 02:37:35
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.14 ----

SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwClose [0xF744C028]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwCreateKey [0xF744BFE0]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwCreatePagingFile [0xF743FB00]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwEnumerateKey [0xF74405DC]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwEnumerateValueKey [0xF744C120]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwOpenFile [0xF743FB40]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwOpenKey [0xF744BFA4]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwQueryKey [0xF74405FC]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwQueryValueKey [0xF744C076]
SSDT            a347bus.sys (Plug and Play BIOS Extension/ )                                                                                                  ZwSetSystemPowerState [0xF744B550]

---- User code sections - GMER 1.0.14 ----

.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28DAA                                                                                   7C9D2175 260 Bytes  [ BD, E4, 77, DE, 82, E4, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28EAF                                                                                   7C9D227A 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28EB1                                                                                   7C9D227C 584 Bytes  [ 85, F1, D3, 77, 04, 06, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE290FA                                                                                   7C9D24C5 383 Bytes  [ 01, D4, 77, 6E, B4, D1, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE2927A                                                                                   7C9D2645 168 Bytes  [ 85, D3, 77, 9F, 01, D2, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 1C2                                                                                         7C9F2AC3 274 Bytes  [ 53, 48, 46, 69, 6E, 64, 5F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 2D5                                                                                         7C9F2BD6 118 Bytes  [ 53, 48, 47, 65, 74, 46, 69, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 34C                                                                                         7C9F2C4D 16 Bytes  [ 53, 48, 47, 65, 74, 46, 6F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 35D                                                                                         7C9F2C5E 94 Bytes  [ 53, 48, 47, 65, 74, 49, 63, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 3BC                                                                                         7C9F2CBD 62 Bytes  [ 53, 48, 47, 65, 74, 4E, 65, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + C0                                                                                       7C9F30BD 48 Bytes  [ 53, 48, 53, 68, 65, 6C, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + F1                                                                                       7C9F30EE 117 Bytes  [ 53, 48, 53, 74, 61, 72, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + 167                                                                                      7C9F3164 217 Bytes  [ 53, 48, 56, 61, 6C, 69, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 9                                                                                          7C9F323E 386 Bytes  [ 53, 68, 65, 53, 65, 74, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 18C                                                                                        7C9F33C1 165 Bytes  [ 74, 72, 43, 68, 72, 49, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 232                                                                                        7C9F3467 72 Bytes  [ 53, 74, 72, 52, 43, 68, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCloneFirst + 12                                                                                    7C9F34B0 218 Bytes  [ 53, 74, 72, 53, 74, 72, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 3C                                                                                       7C9F358B 68 Bytes  [ 68, 49, 73, 52, 65, 6C, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 81                                                                                       7C9F35D0 56 Bytes  [ 55, 8B, EC, FF, 75, 08, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + BD                                                                                       7C9F360C 67 Bytes  [ 8B, FF, 55, 8B, EC, 53, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 101                                                                                      7C9F3650 21 Bytes  [ 00, 00, 8B, F8, 39, 1D, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 117                                                                                      7C9F3666 116 Bytes  [ 15, 68, 1A, 9D, 7C, 5E, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 64                                                                              7C9F3C02 4 Bytes  [ 80, 89, 7D, 0C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 69                                                                              7C9F3C07 1 Byte  [ 15 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 6B                                                                              7C9F3C09 18 Bytes  [ 1B, 9D, 7C, FF, 75, 10, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 7E                                                                              7C9F3C1C 57 Bytes  [ F8, 50, 53, FF, 75, 08, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + B8                                                                              7C9F3C56 29 Bytes  [ 8B, C7, 5F, 5E, C9, C2, 0C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 1                                                                                     7C9F4590 45 Bytes  JMP 7097D097 
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 31                                                                                    7C9F45C0 63 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 71                                                                                    7C9F4600 21 Bytes  [ 00, 8B, 45, 0C, C9, C2, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 87                                                                                    7C9F4616 22 Bytes  [ 8B, C1, 8D, 50, 04, C7, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 9E                                                                                    7C9F462D 12 Bytes  [ 00, 0F, 85, 90, 8C, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 12                                                                                  7C9F4EE6 26 Bytes  [ 5F, 5E, 8B, C3, 5B, 5D, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 2D                                                                                  7C9F4F01 10 Bytes  [ 00, 73, 00, 65, 00, 44, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 38                                                                                  7C9F4F0C 45 Bytes  [ 6B, 00, 74, 00, 6F, 00, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 66                                                                                  7C9F4F3A 13 Bytes  [ 63, 00, 79, 00, 4C, 00, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 74                                                                                  7C9F4F48 27 Bytes  [ 68, 00, 61, 00, 76, 00, 69, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 19                                                                                7C9F50F6 12 Bytes  [ 45, 00, 76, 00, 65, 00, 6E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 26                                                                                7C9F5103 4 Bytes  [ 00, 49, 00, 6E ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 2B                                                                                7C9F5108 7 Bytes  [ 68, 00, 65, 00, 72, 00, 69 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 33                                                                                7C9F5110 47 Bytes  [ 74, 00, 43, 00, 6F, 00, 6E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 63                                                                                7C9F5140 19 Bytes  [ 62, 00, 56, 00, 69, 00, 65, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 66                                                                               7C9F5546 51 Bytes  [ 70, 00, 53, 00, 63, 00, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 9A                                                                               7C9F557A 104 Bytes  [ 75, 00, 6E, 00, 64, 00, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 104                                                                              7C9F55E4 60 Bytes  [ 08, 00, 00, 00, 10, 58, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 141                                                                              7C9F5621 49 Bytes  [ 01, 00, 00, 10, 58, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 173                                                                              7C9F5653 24 Bytes  [ 00, 10, 58, 9D, 7C, E0, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 2A                                                                                    7C9F56D5 13 Bytes  [ 00, 00, 01, 10, 58, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 38                                                                                    7C9F56E3 107 Bytes  [ 02, 10, 58, 9D, 7C, 38, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + A4                                                                                    7C9F574F 79 Bytes  [ 40, 10, 58, 9D, 7C, 20, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + F5                                                                                    7C9F57A0 109 Bytes  [ 09, 00, 00, 40, 10, 58, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 164                                                                                   7C9F580F 46 Bytes  [ 40, 00, 53, 9D, 7C, B0, 51, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 1B                                                                              7C9F6872 111 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 8B                                                                              7C9F68E2 2 Bytes  [ 21, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 8F                                                                              7C9F68E6 19 Bytes  [ 3B, C7, 5F, 0F, 85, FD, 24, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + A3                                                                              7C9F68FA 63 Bytes  [ C0, 75, 03, 8D, 46, 20, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + E4                                                                              7C9F693B 66 Bytes  [ 45, 0C, 5D, C2, 0C, 00, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + 6C                                                                              7C9F6E93 31 Bytes  [ C5, BC, 7C, 89, 45, FC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + 8C                                                                              7C9F6EB3 27 Bytes  CALL 7C9F6E58 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + A8                                                                              7C9F6ECF 46 Bytes  [ 00, 00, 8B, D8, 8B, 4D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + D8                                                                              7C9F6EFF 32 Bytes  [ 8B, 45, 14, 53, 8B, 5D, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + F9                                                                              7C9F6F20 69 Bytes  [ 00, 8D, BD, E4, FB, FF, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath                                                                                     7C9F6FBF 74 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 4B                                                                                7C9F700A 87 Bytes  [ 45, 0C, 57, 8B, F1, 50, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + A3                                                                                7C9F7062 101 Bytes  [ 33, C0, 8B, 4D, FC, 5F, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 109                                                                               7C9F70C8 49 Bytes  [ 50, 56, 89, 85, D8, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 13B                                                                               7C9F70FA 25 Bytes  CALL 7C9F6FC3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + 12                                                                                  7C9F78BF 138 Bytes  [ 7D, 14, 8B, F0, 89, 7D, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + 9D                                                                                  7C9F794A 2 Bytes  [ 5D, 14 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + A0                                                                                  7C9F794D 58 Bytes  [ 45, E4, 8B, 45, 18, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + DC                                                                                  7C9F7989 18 Bytes  [ FF, 75, D8, 8B, 46, 18, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + EF                                                                                  7C9F799C 5 Bytes  [ 57, 0C, 8B, F8, 85 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 16                                                                                          7C9F7AA0 12 Bytes  [ 75, C0, 50, FF, 51, 0C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 23                                                                                          7C9F7AAD 54 Bytes  [ 75, C4, 8D, 45, D0, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 5A                                                                                          7C9F7AE4 67 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 9E                                                                                          7C9F7B28 177 Bytes  [ 50, 8D, 45, F4, 50, 53, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 150                                                                                         7C9F7BDA 12 Bytes  [ 75, 20, FF, 75, 08, FF, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 10                                                                         7C9F7F1E 89 Bytes  [ 64, 00, 69, 00, 6E, 00, 67, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 6A                                                                         7C9F7F78 4 Bytes  [ 66, C7, 03, 19 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 6F                                                                         7C9F7F7D 25 Bytes  [ C6, 43, 02, 2F, 75, 14, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 89                                                                         7C9F7F97 31 Bytes  [ 33, FF, 8B, 4D, FC, 8B, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + AB                                                                         7C9F7FB9 15 Bytes  [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + E                                                                                 7C9F869C 5 Bytes  [ FF, 75, 08, E8, 59 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 14                                                                                7C9F86A2 100 Bytes  [ 00, 00, 85, C0, 75, 41, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 79                                                                                7C9F8707 10 Bytes  [ 00, A1, 08, C5, BC, 7C, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 85                                                                                7C9F8713 6 Bytes  [ 00, 56, 89, 45, FC, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 8C                                                                                7C9F871A 23 Bytes  [ 08, 57, 50, 8B, F9, E8, 17, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 28                                                                             7C9F9829 35 Bytes  [ 83, BD, EC, FD, FF, FF, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 4C                                                                             7C9F984D 43 Bytes  [ 00, 33, DB, 66, 39, 1E, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 79                                                                             7C9F987A 84 Bytes  CALL 7C9F091D C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 4C                                                                      7C9F98CF 13 Bytes  [ 85, FC, FD, FF, FF, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 5A                                                                      7C9F98DD 4 Bytes  [ B5, EC, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 5F                                                                      7C9F98E2 1 Byte  [ 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 61                                                                      7C9F98E4 5 Bytes  [ FC, FD, FF, FF, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 67                                                                      7C9F98EA 11 Bytes  [ 15, 7C, 20, 9D, 7C, 83, BD, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 11                                                                                       7C9F9A7D 5 Bytes  [ 0C, 8D, 8D, DC, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 17                                                                                       7C9F9A83 40 Bytes  CALL 7C9F9A85 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 40                                                                                       7C9F9AAC 25 Bytes  [ 5F, 5E, 5B, 74, 0C, FF, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 5A                                                                                       7C9F9AC6 8 Bytes  CALL 7C9F0920 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 63                                                                                       7C9F9ACF 4 Bytes  [ 90, 90, 90, 90 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 15                                                                            7C9F9D91 6 Bytes  [ C5, BC, 7C, 89, 45, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 1C                                                                            7C9F9D98 44 Bytes  [ 45, 08, 50, 6A, 07, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 49                                                                            7C9F9DC5 44 Bytes  [ 85, C0, 0F, 85, 19, B1, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 76                                                                            7C9F9DF2 31 Bytes  CALL 7C9F9A1E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 96                                                                            7C9F9E12 29 Bytes  [ C0, 0F, 84, 7C, 6E, 02, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealDriveType + 1E                                                                                   7C9F9E9C 23 Bytes  [ 34, 50, FF, 76, 14, E8, 63, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType                                                                                            7C9F9EB6 24 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 19                                                                                       7C9F9ECF 18 Bytes  [ 76, 04, FF, 75, 0C, 53, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 2C                                                                                       7C9F9EE2 69 Bytes  [ 74, 2C, 6A, 00, 8D, 45, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 72                                                                                       7C9F9F28 10 Bytes  [ FF, 55, 8B, EC, 8B, 45, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 7D                                                                                       7C9F9F33 29 Bytes  [ 7F, 0F, 87, CF, 5D, 06, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + B                                                                                       7C9FA04A 151 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + A4                                                                                      7C9FA0E3 3 Bytes  [ 8B, FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + A8                                                                                      7C9FA0E7 122 Bytes  [ EC, 51, 83, 65, FC, 00, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + 123                                                                                     7C9FA162 24 Bytes  [ C7, 5F, 5E, C9, C3, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + 13C                                                                                     7C9FA17B 1 Byte  [ 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 3C                                                                               7C9FADA4 91 Bytes  [ C5, BC, 7C, 56, 8B, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 98                                                                               7C9FAE00 16 Bytes  [ B5, E0, FD, FF, FF, E8, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + A9                                                                               7C9FAE11 55 Bytes  [ 85, E0, FD, FF, FF, 8D, 95, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + E1                                                                               7C9FAE49 56 Bytes  [ 8B, 85, E0, FD, FF, FF, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 11A                                                                              7C9FAE82 3 Bytes  [ EC, 83, EC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 2                                                                               7C9FAFF2 11 Bytes  CALL 7C9FB4F4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + F                                                                               7C9FAFFF 37 Bytes  [ FC, 66, F7, D8, 5F, 5E, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 37                                                                              7C9FB027 19 Bytes  CALL 7C9F3A80 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 4B                                                                              7C9FB03B 5 Bytes  [ 90, 90, 90, 90, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 51                                                                              7C9FB041 30 Bytes  [ 55, 8B, EC, 81, EC, 14, 02, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetImageLists + 5E                                                                             7C9FB158 32 Bytes  [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetImageLists + 80                                                                             7C9FB17A 49 Bytes  [ 00, 53, 8B, 5D, 18, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 27                                                                                  7C9FB1AC 45 Bytes  [ 00, 8D, 85, F4, F5, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 55                                                                                  7C9FB1DA 107 Bytes  [ FF, C9, C2, 18, 00, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + C1                                                                                  7C9FB246 67 Bytes  [ C4, FF, FF, 8D, 85, E4, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 105                                                                                 7C9FB28A 29 Bytes  [ 8B, 55, 10, A1, 08, C5, BC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 123                                                                                 7C9FB2A8 106 Bytes  [ 08, 51, 33, FF, 50, 57, 89, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath                                                                               7C9FB4F4 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 4                                                                           7C9FB4F8 47 Bytes  [ FF, 55, 8B, EC, 56, 8B, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 34                                                                          7C9FB528 10 Bytes  [ C6, 5E, 5D, C2, 08, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 3F                                                                          7C9FB533 62 Bytes  [ 8B, FF, 55, 8B, EC, 81, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 25                                                                                     7C9FB572 29 Bytes  [ FF, C9, C2, 08, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 43                                                                                     7C9FB590 30 Bytes  [ 8B, F1, 47, 83, BE, A4, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 62                                                                                     7C9FB5AF 107 Bytes  [ FF, 8D, 85, EC, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + CE                                                                                     7C9FB61B 170 Bytes  [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 179                                                                                    7C9FB6C6 20 Bytes  [ C7, 06, 80, 7A, 9D, 7C, 74, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsParent + A2                                                                                      7C9FB7B9 116 Bytes  [ 4D, 10, 56, 8B, 75, 0C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 57                                                                                     7C9FB82E 5 Bytes  [ C6, 5E, 5D, C2, 0C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 5D                                                                                     7C9FB834 8 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 66                                                                                     7C9FB83D 10 Bytes  [ EC, 56, 57, 68, 98, 04, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 71                                                                                     7C9FB848 12 Bytes  [ FF, FF, 85, C0, 59, 74, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 7E                                                                                     7C9FB855 7 Bytes  [ 75, 0C, FF, 75, 08, E8, 8F ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 13                                                                          7C9FE90C 38 Bytes  [ 83, 7B, 34, 00, 74, 0C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 3A                                                                          7C9FE933 54 Bytes  [ 80, 74, 17, 5F, 5E, 5B, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 71                                                                          7C9FE96A 13 Bytes  [ 07, 33, C0, 5E, 5D, C2, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 7F                                                                          7C9FE978 83 Bytes  CALL 7C9F4659 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + D3                                                                          7C9FE9CC 42 Bytes  [ 4B, FF, FF, 85, C0, 59, 74, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 4                                                                                 7C9FF77B 5 Bytes  [ 75, 08, 83, 7E, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + A                                                                                 7C9FF781 49 Bytes  [ 74, 1B, 8D, 45, 14, 50, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 3C                                                                                7C9FF7B3 1 Byte  [ F4 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 40                                                                                7C9FF7B7 1 Byte  [ 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 42                                                                                7C9FF7B9 2 Bytes  [ 76, BD ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 11                                                                         7CA0067F 37 Bytes  CALL 7C9FCD0D C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 37                                                                         7CA006A5 302 Bytes  [ A8, 20, 0F, 85, 84, 53, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 167                                                                        7CA007D5 41 Bytes  [ B8, 05, 40, 00, 80, 74, 30, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 191                                                                        7CA007FF 5 Bytes  [ 75, 10, FF, 75, 0C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 198                                                                        7CA00806 54 Bytes  [ 08, 50, FF, 51, 1C, 5B, 5E, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 23                                                                       7CA06AFA 24 Bytes  [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 3C                                                                       7CA06B13 31 Bytes  [ 06, 8B, D9, 57, 8D, 7B, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 5C                                                                       7CA06B33 130 Bytes  [ 55, 8B, EC, 81, EC, 28, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + DF                                                                       7CA06BB6 1 Byte  [ 61 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + E1                                                                       7CA06BB8 1 Byte  [ 6E ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + B1                                                                7CA07377 18 Bytes  [ 55, 8B, EC, 8B, 45, 08, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + C6                                                                7CA0738C 5 Bytes  [ 8B, FF, 55, 8B, EC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + CC                                                                7CA07392 49 Bytes  [ 45, 08, 56, 57, 8B, 7D, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + FE                                                                7CA073C4 41 Bytes  CALL 7C9F6B73 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + 128                                                               7CA073EE 61 Bytes  [ C8, 23, 4D, 0C, 3B, C8, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + B                                                                  7CA07E84 3 Bytes  [ C2, 5F, 05 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + F                                                                  7CA07E88 1 Byte  [ 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 11                                                                 7CA07E8A 77 Bytes  CALL 061D3B9E 
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 5F                                                                 7CA07ED8 65 Bytes  [ 0F, 84, 9A, 45, 05, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + A1                                                                 7CA07F1A 48 Bytes  [ FF, 55, 8B, EC, 8D, 81, 64, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 2                                                                                7CA0997A 29 Bytes  JMP 7CA098F4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 20                                                                               7CA09998 25 Bytes  [ 55, 8B, EC, 83, EC, 40, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 3A                                                                               7CA099B2 30 Bytes  [ 84, AE, 1B, 00, 00, 56, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 59                                                                               7CA099D1 108 Bytes  [ 1E, 05, 00, 8D, 45, 0C, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 15                                                                                 7CA09A3E 10 Bytes  [ FF, 43, 83, C7, 1C, 3B, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 20                                                                                 7CA09A49 23 Bytes  [ 76, 38, 68, 02, 00, 00, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 39                                                                                 7CA09A62 4 Bytes  CALL 7CA09838 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 3E                                                                                 7CA09A67 53 Bytes  [ FF, 83, 7E, 3C, 00, 5B, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 75                                                                                 7CA09A9E 3 Bytes  [ 90, 90, 90 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 6                                                                                    7CA0A619 56 Bytes  [ 08, 50, FF, 51, 08, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 3F                                                                                   7CA0A652 66 Bytes  CALL 7C9F5F71 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 82                                                                                   7CA0A695 19 Bytes  [ 07, 80, EB, E0, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 96                                                                                   7CA0A6A9 30 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + B5                                                                                   7CA0A6C8 45 Bytes  [ FF, 15, 0C, 13, 9D, 7C, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 24                                                                     7CA0A752 23 Bytes  [ 8B, 75, 10, F7, C6, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 3C                                                                     7CA0A76A 90 Bytes  [ 15, 56, 53, FF, B5, EC, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 97                                                                     7CA0A7C5 33 Bytes  [ FF, 89, 85, E4, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + BA                                                                     7CA0A7E8 2 Bytes  [ 85, C0 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + BD                                                                     7CA0A7EB 3 Bytes  [ 85, D3, 4A ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 1B                                                                                  7CA0AC42 64 Bytes  [ 90, 90, 90, 90, 90, 90, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 5D                                                                                  7CA0AC84 41 Bytes  [ D0, 9C, A0, 7C, B4, 9C, A0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 87                                                                                  7CA0ACAE 4 Bytes  [ 31, 00, 33, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 8C                                                                                  7CA0ACB3 34 Bytes  [ 00, 66, 00, 70, 00, 69, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + AF                                                                                  7CA0ACD6 7 Bytes  [ 69, 00, 63, 00, 6F, 00, 6E ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 9D                                                                                  7CA0C403 57 Bytes  [ 46, 54, 50, FF, D7, 8B, 8E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + D7                                                                                  7CA0C43D 111 Bytes  [ F1, 6A, 00, FF, 36, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 147                                                                                 7CA0C4AD 42 Bytes  [ 46, 08, 85, C0, 74, 0B, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 172                                                                                 7CA0C4D8 42 Bytes  [ 15, A0, 1C, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 19D                                                                                 7CA0C503 15 Bytes  [ FF, 90, 90, 90, 90, 90, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 2C                                                                            7CA0D669 19 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 40                                                                            7CA0D67D 16 Bytes  [ 00, FF, 75, 08, 8B, F1, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 51                                                                            7CA0D68E 28 Bytes  [ 42, 83, 7E, 54, 00, 75, 0A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 6E                                                                            7CA0D6AB 38 Bytes  [ 51, 18, 8B, F8, 85, FF, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 95                                                                            7CA0D6D2 75 Bytes  [ C7, 5F, 5E, C9, C2, 04, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 23                                                                                       7CA0DB6B 18 Bytes  [ 85, B0, FB, FF, FF, 83, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 36                                                                                       7CA0DB7E 14 Bytes  [ FF, 85, C0, 0F, 85, 46, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 45                                                                                       7CA0DB8D 19 Bytes  CALL 7CA0DBA4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 5C                                                                                       7CA0DBA4 115 Bytes  [ 90, 8B, FF, 55, 8B, EC, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + D0                                                                                       7CA0DC18 17 Bytes  [ 59, 9D, 7C, FF, B5, B4, FB, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 23                                                                                      7CA0DE8C 9 Bytes  [ 85, C0, 74, 1E, 8B, 45, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 2E                                                                                      7CA0DE97 3 Bytes  [ AA, F1, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 32                                                                                      7CA0DE9B 96 Bytes  [ 8D, 48, 04, 6A, 01, E8, F1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 93                                                                                      7CA0DEFC 48 Bytes  [ 15, 68, 13, 9D, 7C, E9, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + C4                                                                                      7CA0DF2D 45 Bytes  JMP 7CA053AA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 4B                                                                               7CA0E774 5 Bytes  [ FF, 8B, CE, E8, 0A ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 52                                                                               7CA0E77B 5 Bytes  [ 00, E9, 52, F6, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 58                                                                               7CA0E781 117 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + CE                                                                               7CA0E7F7 129 Bytes  [ 75, 10, FF, 75, FC, E8, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 150                                                                              7CA0E879 95 Bytes  [ 59, 33, C0, EB, F1, 8B, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile                                                                                      7CA0EE68 115 Bytes  [ 90, 8B, FF, 55, 8B, EC, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + 74                                                                                 7CA0EEDC 22 Bytes  [ 4D, FC, 5F, 5E, 5B, E8, 3A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + 8B                                                                                 7CA0EEF3 83 Bytes  [ EC, 56, 57, 6A, 01, 33, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + E0                                                                                 7CA0EF48 23 Bytes  [ 00, 8B, F8, F7, C7, 00, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + F8                                                                                 7CA0EF60 43 Bytes  [ 90, E4, 00, 00, 00, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + 2                                                                     7CA0F22E 152 Bytes  [ 7C, 65, 53, FF, 15, 8C, 1A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + 9B                                                                    7CA0F2C7 10 Bytes  [ 15, A0, 1A, 9D, 7C, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + A7                                                                    7CA0F2D3 76 Bytes  [ 33, C0, EB, F8, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + F6                                                                    7CA0F322 2 Bytes  [ 5F, 5E ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + FA                                                                    7CA0F326 1 Byte  [ 15 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathCleanupSpec + 79                                                                                 7CA0F488 11 Bytes  [ FF, 15, 00, 13, 9D, 7C, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathCleanupSpec + 85                                                                                 7CA0F494 66 Bytes  CALL 7CA0F679 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 2A                                                                               7CA0F4D7 11 Bytes  [ B5, DC, FD, FF, FF, 8B, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 36                                                                               7CA0F4E3 4 Bytes  [ 89, 85, E0, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 3C                                                                               7CA0F4E9 1 Byte  [ 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 3E                                                                               7CA0F4EB 2 Bytes  [ F0, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 42                                                                               7CA0F4EF 75 Bytes  [ 50, FF, B5, EC, FD, FF, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + D                                                                                         7CA0FB18 181 Bytes  [ 75, 08, FF, 15, A0, 1A, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + C3                                                                                        7CA0FBCE 25 Bytes  [ 53, 8D, 45, FC, 50, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + DD                                                                                        7CA0FBE8 3 Bytes  [ 46, 1C, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + E1                                                                                        7CA0FBEC 26 Bytes  [ 53, FF, 75, FC, FF, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + FC                                                                                        7CA0FC07 50 Bytes  CALL 7CA0FC3C C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + 16                                                                        7CA0FCD5 7 Bytes  [ B5, D8, F7, FF, FF, 53, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + 1E                                                                        7CA0FCDD 159 Bytes  [ 18, 85, C0, 0F, 8D, D8, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + BE                                                                        7CA0FD7D 4 Bytes  [ 85, C0, 7C, 2B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + C3                                                                        7CA0FD82 7 Bytes  [ 55, 10, 8B, 45, FC, 8B, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + CB                                                                        7CA0FD8A 37 Bytes  [ E2, 01, F6, DA, 1B, D2, 81, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + 76                                                                                 7CA1162F 31 Bytes  [ 00, 83, 4D, F8, FF, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + 97                                                                                 7CA11650 30 Bytes  [ 00, 89, 7D, F4, 89, 7D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + B6                                                                                 7CA1166F 14 Bytes  [ 01, 6A, 01, FF, 50, 14, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + C5                                                                                 7CA1167E 46 Bytes  [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + F4                                                                                 7CA116AD 31 Bytes  [ 5B, C9, C3, 90, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 2                                                                                      7CA11FE6 92 Bytes  [ 50, 10, 85, C0, 0F, 8C, 31, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 5F                                                                                     7CA12043 51 Bytes  JMP 7CA11C85 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 94                                                                                     7CA12078 5 Bytes  [ 9D, 7C, 2B, F9, C1 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 9A                                                                                     7CA1207E 27 Bytes  [ 02, 03, F1, 8B, 16, 03, D9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + B6                                                                                     7CA1209A 49 Bytes  [ 9D, 7C, 85, D2, 89, 45, FC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + B                                                                                    7CA136EF 1 Byte  [ 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + D                                                                                    7CA136F1 31 Bytes  [ F8, 50, FF, 75, F8, 53, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 2D                                                                                   7CA13711 56 Bytes  [ 15, 8C, 1A, 9D, 7C, 8D, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 66                                                                                   7CA1374A 32 Bytes  [ 15, E4, 20, 9D, 7C, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 87                                                                                   7CA1376B 6 Bytes  [ 15, 28, 19, 9D, 7C, 8B ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 3E                                                                                  7CA13AB7 35 Bytes  CALL 7C9F3A80 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 62                                                                                  7CA13ADB 318 Bytes  [ FD, FF, FF, 50, FF, 15, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 1A1                                                                                 7CA13C1A 48 Bytes  [ 88, 98, 02, 00, 00, 89, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 1D2                                                                                 7CA13C4B 62 Bytes  [ 00, 3B, CA, 0F, 85, 54, FA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 211                                                                                 7CA13C8A 8 Bytes  [ C9, C2, 08, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 2                                                                        7CA18B23 24 Bytes  [ 15, F0, 18, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 1B                                                                       7CA18B3C 44 Bytes  [ EC, FD, FF, FF, 0F, 8C, 7F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 48                                                                       7CA18B69 54 Bytes  [ 57, 68, 7D, 00, 00, 40, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 7F                                                                       7CA18BA0 39 Bytes  [ F6, 87, 59, 06, 00, 00, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + A7                                                                       7CA18BC8 116 Bytes  [ F0, 3B, F3, 0F, 8C, 8D, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 1F                                                                                7CA19F90 103 Bytes  CALL 7CA0068E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 87                                                                                7CA19FF8 9 Bytes  [ 0F, 84, 28, BC, 03, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 91                                                                                7CA1A002 52 Bytes  CALL 7C9FFFB8 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + C6                                                                                7CA1A037 75 Bytes  [ 00, 8B, 4E, 14, 6A, 02, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 112                                                                               7CA1A083 23 Bytes  [ 80, 8E, 11, 02, 00, 00, 04, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 25                                                                            7CA1A324 42 Bytes  CALL 7C9F968E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 50                                                                            7CA1A34F 59 Bytes  [ 85, F4, FD, FF, FF, 50, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 8D                                                                            7CA1A38C 27 Bytes  [ 01, E4, FD, FF, 50, 68, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + A9                                                                            7CA1A3A8 25 Bytes  [ FF, FF, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + C3                                                                            7CA1A3C2 8 Bytes  [ 18, 83, 7D, 0C, 00, 8D, 04, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 96                                                                                    7CA1B0BB 37 Bytes  [ 00, 89, 85, F0, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + BC                                                                                    7CA1B0E1 43 Bytes  [ 56, 8B, 75, 14, 83, 26, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + E8                                                                                    7CA1B10D 40 Bytes  [ 75, 10, 8D, 55, 08, 52, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 111                                                                                   7CA1B136 11 Bytes  JMP 7CA0C4E5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 11D                                                                                   7CA1B142 23 Bytes  [ 55, 8B, EC, 51, 53, 8B, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 59                                                                              7CA1C1C4 10 Bytes  [ CE, FF, 50, 14, 8B, C7, 5F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 64                                                                              7CA1C1CF 9 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 6E                                                                              7CA1C1D9 8 Bytes  [ EC, 56, 8B, F1, E8, 19, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 77                                                                              7CA1C1E2 19 Bytes  [ F6, 45, 08, 01, 74, 07, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 8B                                                                              7CA1C1F6 34 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 5D                                                                                     7CA1D37A 9 Bytes  [ FF, 15, 1C, 18, 9D, 7C, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 67                                                                                     7CA1D384 6 Bytes  [ D8, 0F, 84, 29, 01, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 6E                                                                                     7CA1D38B 277 Bytes  [ 8B, 08, 8D, 55, EC, 52, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 2                                                                                  7CA1D4A1 37 Bytes  [ 75, 0C, 68, B4, E0, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 28                                                                                 7CA1D4C7 62 Bytes  [ 75, 0C, 8B, 45, 08, 83, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 67                                                                                 7CA1D506 6 Bytes  [ 68, 20, E1, 9D, 7C, 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 6E                                                                                 7CA1D50D 62 Bytes  CALL 7C9FBE95 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + AD                                                                                 7CA1D54C 71 Bytes  [ 6A, 20, 8D, 45, DC, 50, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSettings + 32                                                                                   7CA1D5F0 12 Bytes  [ D0, 8B, 08, 50, FF, 51, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW                                                                                      7CA1D5FE 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 4                                                                                  7CA1D602 109 Bytes  [ FF, 55, 8B, EC, 56, 57, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 72                                                                                 7CA1D670 39 Bytes  [ 48, 0C, 8B, D1, 57, C1, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 9B                                                                                 7CA1D699 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 9F                                                                                 7CA1D69D 37 Bytes  [ FF, 55, 8B, EC, 56, 68, 48, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + F                                                                                   7CA1FB2B 48 Bytes  [ 55, 8B, EC, 81, EC, 90, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 40                                                                                  7CA1FB5C 4 Bytes  [ FF, FF, 51, 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 45                                                                                  7CA1FB61 2 Bytes  [ 7C, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 49                                                                                  7CA1FB65 19 Bytes  [ 51, 6A, 04, 50, 6A, 01, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 5D                                                                                  7CA1FB79 79 Bytes  [ FF, FF, 74, 11, 6A, 01, 57, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 94                                                                                   7CA1FED8 56 Bytes  [ 53, 00, 68, 00, 65, 00, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + D1                                                                                   7CA1FF15 405 Bytes  [ 8B, FF, 55, 8B, EC, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 267                                                                                  7CA200AB 246 Bytes  [ 00, 56, FF, 75, 0C, E8, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 35E                                                                                  7CA201A2 68 Bytes  [ A1, 08, C5, BC, 7C, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 3A3                                                                                  7CA201E7 24 Bytes  [ 15, 40, 1D, 9D, 7C, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 3A                                                                           7CA21BB7 42 Bytes  [ 68, 41, 01, 00, 00, 68, AC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 65                                                                           7CA21BE2 56 Bytes  [ 66, 3B, C3, 66, A3, 48, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 9E                                                                           7CA21C1B 35 Bytes  [ FF, 15, 1C, 18, 9D, 7C, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + C2                                                                           7CA21C3F 4 Bytes  [ 15, 10, 17, 9D ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + C7                                                                           7CA21C44 15 Bytes  [ 3B, C6, 74, 11, 68, 48, 7F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 14                                                                                   7CA220E2 31 Bytes  [ 50, 68, 28, 11, A2, 7C, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 34                                                                                   7CA22102 14 Bytes  [ 53, 50, 68, 00, 00, 00, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 43                                                                                   7CA22111 4 Bytes  [ 85, 14, 08, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 48                                                                                   7CA22116 27 Bytes  [ 66, 89, 1E, 8B, 4D, FC, 5F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 64                                                                                   7CA22132 97 Bytes  [ 63, 00, 61, 00, 74, 00, 69, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + 10                                                                                    7CA222D8 81 Bytes  [ 00, 83, 7D, 10, 00, A1, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + 62                                                                                    7CA2232A 68 Bytes  [ BF, 10, 43, 9D, 7C, 33, D2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + A7                                                                                    7CA2236F 14 Bytes  [ FF, B5, F0, FD, FF, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + B6                                                                                    7CA2237E 20 Bytes  [ C6, 5F, 8B, 4D, FC, 5E, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + CD                                                                                    7CA22395 41 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 5                                                                              7CA23AB6 57 Bytes  [ 56, 57, 6A, 01, 6A, 01, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 3F                                                                             7CA23AF0 35 Bytes  CALL 7C9F38FF C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 63                                                                             7CA23B14 29 Bytes  JMP 7CA09B63 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 81                                                                             7CA23B32 59 Bytes  CALL 7C9F8B87 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + BD                                                                             7CA23B6E 111 Bytes  [ 15, 70, FC, 9E, 7C, 50, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 6A                                                                                       7CA2461B 8 Bytes  [ EC, 10, 53, 56, C7, 45, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 73                                                                                       7CA24624 5 Bytes  [ 00, 00, C6, 45, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 79                                                                                       7CA2462A 14 Bytes  CALL 7CA243CF C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 88                                                                                       7CA24639 52 Bytes  [ 8B, 75, 08, 6A, 00, 6A, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + BD                                                                                       7CA2466E 10 Bytes  [ 68, F8, B0, 9D, 7C, E8, 4B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 55                                                                                7CA2496B 6 Bytes  [ 04, 59, 33, C0, F3, A7 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 5C                                                                                7CA24972 58 Bytes  [ E4, 8B, 45, FC, 5F, 5E, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 97                                                                                7CA249AD 65 Bytes  [ F8, 3B, FE, 0F, 8C, 2F, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + D9                                                                                7CA249EF 2 Bytes  [ 0F, 94 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + DC                                                                                7CA249F2 70 Bytes  [ C1, E0, 09, 33, 06, 25, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 25                                                                           7CA2A12B 68 Bytes  [ 15, 68, AF, 9F, 7C, 83, A0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 6A                                                                           7CA2A170 5 Bytes  [ 72, EA, FF, 75, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 70                                                                           7CA2A176 96 Bytes  [ 45, 08, 57, 68, 3A, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + D1                                                                           7CA2A1D7 1 Byte  [ F0 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + D3                                                                           7CA2A1D9 30 Bytes  [ 02, C1, E0, 02, 50, 51, 52, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 31                                                                               7CA2B7F5 14 Bytes  [ 90, 90, 90, 8B, FF, 53, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 40                                                                               7CA2B804 145 Bytes  [ 6C, 9D, 7C, C7, 46, 04, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + D2                                                                               7CA2B896 49 Bytes  [ 00, 8D, 0C, 40, 8D, BC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 104                                                                              7CA2B8C8 98 Bytes  [ 08, 85, C0, 56, 8B, F1, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 167                                                                              7CA2B92B 3 Bytes  [ 45, FC, 39 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 23                                                                                   7CA2BFC9 44 Bytes  [ 10, 8B, F8, 8B, 06, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 50                                                                                   7CA2BFF6 40 Bytes  [ C0, 0F, 84, 21, 3B, 03, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 79                                                                                   7CA2C01F 43 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + A5                                                                                   7CA2C04B 14 Bytes  [ 56, FF, 35, 64, C5, BC, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + B4                                                                                   7CA2C05A 49 Bytes  [ 15, 1C, 16, 9D, 7C, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 19                                                                              7CA2C890 17 Bytes  CALL 7CA2C89F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 2B                                                                              7CA2C8A2 79 Bytes  [ 55, 8B, EC, 83, EC, 7C, A1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 7B                                                                              7CA2C8F2 57 Bytes  [ D7, 85, C0, 75, 5E, FF, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + B5                                                                              7CA2C92C 9 Bytes  CALL 7CA0F6D7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + BF                                                                              7CA2C936 145 Bytes  [ 45, 8C, 8B, 08, 50, FF, 51, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 3D                                                                               7CA2FD4E 48 Bytes  [ C1, FD, FF, FF, 08, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 6E                                                                               7CA2FD7F 27 Bytes  [ 76, 28, 33, DB, 8D, 85, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 8A                                                                               7CA2FD9B 13 Bytes  [ F1, FF, FF, 8B, 85, F4, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 98                                                                               7CA2FDA9 30 Bytes  [ 40, 89, 85, F8, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + B7                                                                               7CA2FDC8 103 Bytes  [ FF, FF, 8D, 4E, FC, E8, 46, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 2F                                                                        7CA39578 75 Bytes  JMP 7CA399C9 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 7C                                                                        7CA395C5 4 Bytes  [ 8B, 4B, 64, 6A ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 81                                                                        7CA395CA 9 Bytes  [ 6A, FF, 56, 6A, 01, E8, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 8B                                                                        7CA395D4 3 Bytes  [ 83, 7B, 64 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 8F                                                                        7CA395D8 5 Bytes  [ 0F, 84, EB, 03, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 37                                                                   7CA3BB45 7 Bytes  [ 00, 33, C9, E9, 14, FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 3F                                                                   7CA3BB4D 25 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 5A                                                                   7CA3BB68 56 Bytes  [ FF, 86, 0C, 01, 00, 00, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 93                                                                   7CA3BBA1 155 Bytes  [ E2, FF, FF, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 130                                                                  7CA3BC3E 66 Bytes  [ 90, 90, 90, 90, 90, 6A, 20, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 32                                                                       7CA40E0E 2 Bytes  [ A0, 1A ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 36                                                                       7CA40E12 26 Bytes  [ F6, 86, 12, 02, 00, 00, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 51                                                                       7CA40E2D 91 Bytes  [ FC, FF, 6A, 16, FF, 15, C8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 2C                                                                            7CA40E89 85 Bytes  [ 15, 68, 1A, 9D, 7C, 5F, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 82                                                                            7CA40EDF 10 Bytes  [ 15, 28, C3, BC, 7C, 8D, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 8D                                                                            7CA40EEA 15 Bytes  CALL 7CA40F2E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 9D                                                                            7CA40EFA 5 Bytes  [ 08, 50, FF, 91, 94 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + A3                                                                            7CA40F00 90 Bytes  [ 00, 00, 57, 57, 8B, D8, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 5                                                                           7CA418F4 190 Bytes  [ 00, 85, C0, 0F, 84, A2, F9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + C4                                                                          7CA419B3 21 Bytes  JMP 7CA215AD C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + DA                                                                          7CA419C9 71 Bytes  JMP 7C9FDF59 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 122                                                                         7CA41A11 28 Bytes  [ 45, F8, 50, 68, A0, 98, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 140                                                                         7CA41A2F 18 Bytes  CALL 7CA41A4F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + 17                                                                              7CA4352D 2 Bytes  [ 88, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + 1B                                                                              7CA43531 133 Bytes  [ 6A, 07, 59, 33, F6, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + A3                                                                              7CA435B9 28 Bytes  [ 8B, 85, 8C, FD, FF, FF, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + C0                                                                              7CA435D6 40 Bytes  [ C9, C2, 10, 00, FF, 76, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + E9                                                                              7CA435FF 28 Bytes  [ 50, 68, 8C, 59, 9D, 7C, 68, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 2B                                                                                  7CA43673 66 Bytes  CALL 7CA4367A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 6E                                                                                  7CA436B6 53 Bytes  [ 55, 8B, EC, FF, 75, 10, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + A4                                                                                  7CA436EC 25 Bytes  [ E0, 8D, 45, 08, 50, 8B, CB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + BE                                                                                  7CA43706 185 Bytes  [ EC, 83, EC, 2C, A1, 08, C5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 178                                                                                 7CA437C0 39 Bytes  [ 55, 8B, EC, 83, 7D, 0C, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + B                                                                        7CA45FE3 103 Bytes  [ D8, 8B, C7, 69, C0, E8, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 73                                                                       7CA4604B 24 Bytes  [ 15, 3C, 12, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 8C                                                                       7CA46064 140 Bytes  [ 74, 30, FF, 75, 30, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 119                                                                      7CA460F1 44 Bytes  [ 35, 64, C5, BC, 7C, C7, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 146                                                                      7CA4611E 11 Bytes  [ 8D, 46, 01, 6A, 05, 89, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 83                                                                          7CA478DD 19 Bytes  [ BC, 98, D4, 02, 00, 00, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 97                                                                          7CA478F1 138 Bytes  [ 15, 84, 1A, 9D, 7C, 8B, F0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 123                                                                         7CA4797D 25 Bytes  [ FF, 75, 18, 8B, 4D, 08, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 13D                                                                         7CA47997 42 Bytes  [ D2, 8B, 4D, 08, 75, 13, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 168                                                                         7CA479C2 36 Bytes  [ 75, 0C, FF, 15, C8, 13, 9D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + A                                                                              7CA47C25 82 Bytes  [ 00, 00, 83, F8, F9, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + 5D                                                                             7CA47C78 70 Bytes  CALL 7CA07EE7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + A5                                                                             7CA47CC0 10 Bytes  [ 57, FF, 15, 2C, 13, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + B0                                                                             7CA47CCB 9 Bytes  [ FF, 6A, 01, 8B, CE, E8, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + BB                                                                             7CA47CD6 84 Bytes  [ 15, 0C, 14, 9D, 7C, 3B, 86, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 4A                                                                               7CA47D2B 83 Bytes  [ 80, 5D, C2, 10, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 9E                                                                               7CA47D7F 5 Bytes  [ 75, 0C, 8B, 08, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + A4                                                                               7CA47D85 25 Bytes  [ 51, 40, 5D, C2, 08, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + BE                                                                               7CA47D9F 65 Bytes  [ 91, A4, 00, 00, 00, 5D, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 100                                                                              7CA47DE1 18 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 1E                                                                                7CA483CE 11 Bytes  [ B5, E4, FD, FF, FF, FF, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 2A                                                                                7CA483DA 44 Bytes  [ 15, B0, 98, A4, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 57                                                                                7CA48407 25 Bytes  [ FF, B5, E0, FD, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 71                                                                                7CA48421 14 Bytes  [ 7C, 9E, FF, B5, D8, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + BC                                                                                7CA4846C 141 Bytes  CALL 7CA47FCC C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 61                                                              7CA484FA 26 Bytes  [ 57, FF, 15, D4, 12, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 7D                                                              7CA48516 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 81                                                              7CA4851A 66 Bytes  [ FF, 55, 8B, EC, 56, 6A, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + C4                                                              7CA4855D 11 Bytes  JMP 7CA47FB7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + D0                                                              7CA48569 14 Bytes  [ FF, 55, 8B, EC, 81, EC, 0C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 24                                                                                7CA48A0B 47 Bytes  [ C7, 85, AC, FB, FF, FF, 3C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 54                                                                                7CA48A3B 58 Bytes  [ FF, 04, 8D, 85, AC, FB, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 8F                                                                                7CA48A76 84 Bytes  [ FF, 55, 8B, EC, 83, 3D, 3C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + E5                                                                                7CA48ACC 37 Bytes  [ FF, 75, 08, FF, 76, 08, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 10B                                                                               7CA48AF2 17 Bytes  [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 3C                                                                           7CA492A5 73 Bytes  [ 00, 00, 5F, 5E, 8B, C3, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 86                                                                           7CA492EF 41 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + B1                                                                           7CA4931A 36 Bytes  [ FF, 77, 10, FF, 15, 8C, 13, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + D6                                                                           7CA4933F 59 Bytes  [ 47, 08, 83, 38, 01, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 112                                                                          7CA4937B 124 Bytes  [ 55, 8B, EC, 56, FF, 75, 14, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 1C                                                                                  7CA49A73 57 Bytes  [ FF, 04, 8B, 3D, F0, 20, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 56                                                                                  7CA49AAD 1 Byte  [ FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 58                                                                                  7CA49AAF 27 Bytes  CALL 7CA48CDD C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 74                                                                                  7CA49ACB 31 Bytes  [ 00, 0F, 84, 69, 08, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 94                                                                                  7CA49AEB 36 Bytes  [ 00, 0F, 84, A7, F2, FF, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 39                                                                                 7CA4A270 93 Bytes  [ 25, AC, 19, 9D, 7C, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 97                                                                                 7CA4A2CE 35 Bytes  [ FF, 33, C0, 66, 3B, 0F, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + BB                                                                                 7CA4A2F2 18 Bytes  [ A0, C0, 00, 00, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + D1                                                                                 7CA4A308 85 Bytes  CALL 7C9F3779 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 127                                                                                7CA4A35E 3 Bytes  [ AA, 92, FA ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutW + 40                                                                                     7CA6F92B 67 Bytes  [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 35                                                                                     7CA6F96F 19 Bytes  [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 49                                                                                     7CA6F983 47 Bytes  [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 79                                                                                     7CA6F9B3 35 Bytes  [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 9D                                                                                     7CA6F9D7 16 Bytes  [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + AE                                                                                     7CA6F9E8 46 Bytes  [ 01, 00, 00, 00, 01, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinW + 55                                                                              7CA732CE 62 Bytes  [ FF, FF, 15, F8, 20, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 2                                                                               7CA7330D 33 Bytes  [ 15, 0C, 1A, 9D, 7C, 8D, 86, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 24                                                                              7CA7332F 21 Bytes  [ 15, F4, B9, 9F, 7C, 83, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 3A                                                                              7CA73345 19 Bytes  [ FF, 50, FF, 75, 14, E8, E1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 4E                                                                              7CA73359 2 Bytes  [ 8D, 85 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 51                                                                              7CA7335C 66 Bytes  [ FB, FF, FF, FF, 75, 10, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 2                                                                               7CA7360C 6 Bytes  [ FF, 53, E8, 3B, EE, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 9                                                                               7CA73613 30 Bytes  [ 39, B5, DC, F9, FF, FF, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 29                                                                              7CA73633 31 Bytes  [ 18, 01, 00, 00, 74, 08, 39, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 4A                                                                              7CA73654 14 Bytes  CALL 7CA70A88 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 59                                                                              7CA73663 62 Bytes  [ 8D, 1C, 9D, D8, 18, BD, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 2E                                                                              7CA736A2 89 Bytes  [ 35, 64, C5, BC, 7C, E8, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 88                                                                              7CA736FC 110 Bytes  [ 56, 0F, 94, C1, 56, 56, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + F7                                                                              7CA7376B 65 Bytes  [ FF, 0F, 94, C0, 89, 41, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 139                                                                             7CA737AD 5 Bytes  [ FF, 8D, 85, DC, F7 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 140                                                                             7CA737B4 54 Bytes  CALL 7CA71F64 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 18                                                                           7CA737EB 112 Bytes  [ 85, C0, 0F, 84, 4A, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 89                                                                           7CA7385C 183 Bytes  [ 8D, 85, DC, F7, FF, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 141                                                                          7CA73914 24 Bytes  [ D8, BE, 04, 01, 00, 00, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 15A                                                                          7CA7392D 13 Bytes  [ 08, FE, FF, FF, 50, 57, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 168                                                                          7CA7393B 63 Bytes  [ 32, 68, AC, DE, 9D, 7C, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 7E                                                                               7CA73B36 54 Bytes  [ 15, CC, 20, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + B5                                                                               7CA73B6D 15 Bytes  [ FF, 00, EB, 0C, FF, 15, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + C5                                                                               7CA73B7D 135 Bytes  [ 83, BD, BC, F7, FF, FF, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 14D                                                                              7CA73C05 7 Bytes  [ 15, A4, 20, 9D, 7C, 57, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 155                                                                              7CA73C0D 39 Bytes  [ B5, D8, F7, FF, FF, 89, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 2E                                                                              7CA75A9F 59 Bytes  [ FF, 89, 9E, 18, 02, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 6A                                                                              7CA75ADB 22 Bytes  [ 07, 3B, C3, 74, 09, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 81                                                                              7CA75AF2 19 Bytes  [ 15, 54, 1A, 9D, 7C, 89, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 95                                                                              7CA75B06 19 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + A9                                                                              7CA75B1A 20 Bytes  [ 76, 04, 33, DB, 89, 5D, FC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectory + 7                                                                                7CA7727C 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectory + 9                                                                                7CA7727E 18 Bytes  [ 41, 56, 8B, 75, 08, 57, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 1                                                                             7CA77291 15 Bytes  CALL 7CA7712F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 11                                                                            7CA772A1 23 Bytes  [ FF, 15, DC, 12, 9D, 7C, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 29                                                                            7CA772B9 1 Byte  [ 15 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 2B                                                                            7CA772BB 48 Bytes  [ 13, 9D, 7C, 5F, 5E, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 5D                                                                            7CA772ED 22 Bytes  [ 00, 8B, 51, 34, 85, D2, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 24                                                                                7CA7D1DD 27 Bytes  [ 00, 8B, 86, A4, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 41                                                                                7CA7D1FA 225 Bytes  [ 00, C7, 46, 3C, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 123                                                                               7CA7D2DC 11 Bytes  [ A1, 08, C5, BC, 7C, 53, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 12F                                                                               7CA7D2E8 8 Bytes  [ FC, 8B, 45, 0C, 57, 8B, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 138                                                                               7CA7D2F1 56 Bytes  [ 40, 85, C0, BF, 00, 01, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 4B                                                                                 7CA7D4EC 41 Bytes  [ FF, 8D, 85, F4, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 75                                                                                 7CA7D516 67 Bytes  [ 85, F4, FD, FF, FF, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + B9                                                                                 7CA7D55A 56 Bytes  [ FF, EB, 2B, 8B, 3D, F4, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + F2                                                                                 7CA7D593 16 Bytes  [ FF, 8B, 46, 40, 85, C0, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 103                                                                                7CA7D5A4 36 Bytes  [ FF, 00, 01, 00, 00, 75, 19, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + 59                                                                        7CA7E03E 88 Bytes  [ 00, 50, 8D, 86, F4, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + B2                                                                        7CA7E097 5 Bytes  [ 50, 8D, 86, F4, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + B9                                                                        7CA7E09E 91 Bytes  CALL 7CA783B7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 20                                                                       7CA7E0FA 38 Bytes  [ B5, 04, F9, FF, FF, E8, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 47                                                                       7CA7E121 29 Bytes  [ 83, F8, FF, 74, 11, 8D, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 65                                                                       7CA7E13F 11 Bytes  [ FF, 68, 04, 01, 00, 00, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 71                                                                       7CA7E14B 7 Bytes  [ 8D, 85, B4, FD, FF, FF, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 79                                                                       7CA7E153 108 Bytes  [ 15, F4, 20, 9D, 7C, 56, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRunControlPanel + E                                                                                7CA7ECAF 2 Bytes  [ 8B, FE ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRunControlPanel + 14                                                                               7CA7ECB5 1 Byte  [ 1C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 5                                                                                   7CA7ECC1 13 Bytes  [ FF, 75, 20, FF, 75, 1C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 13                                                                                  7CA7ECCF 6 Bytes  [ 10, FF, 75, 0C, FF, 75 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 1A                                                                                  7CA7ECD6 13 Bytes  [ 68, 90, 77, 9E, 7C, 68, 58, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 29                                                                                  7CA7ECE5 87 Bytes  [ 5D, C2, 1C, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLW + 28                                                                                 7CA7ED3D 137 Bytes  [ D6, 66, 85, C0, 74, 3C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 59                                                                           7CA7EDC7 36 Bytes  [ D6, 68, 68, 12, 9E, 7C, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 7F                                                                           7CA7EDED 3 Bytes  [ EB, 38, 66 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 83                                                                           7CA7EDF1 14 Bytes  [ 65, BC, 00, 85, DB, 74, 0D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 92                                                                           7CA7EE00 15 Bytes  [ 15, 94, 13, 9D, 7C, 83, 65, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + A2                                                                           7CA7EE10 124 Bytes  [ 45, B8, 89, 45, B0, 8D, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DuplicateIcon + 33                                                                                   7CA7F406 47 Bytes  [ 83, 20, 00, EB, 4D, 8B, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DuplicateIcon + 63                                                                                   7CA7F436 136 Bytes  [ 9D, 7C, 8B, 85, E4, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FreeIconList + 36                                                                                    7CA7F4BF 14 Bytes  [ 15, CC, 1F, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FreeIconList + 45                                                                                    7CA7F4CE 55 Bytes  [ 85, C9, 74, 2A, 8B, 83, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 1C                                                                             7CA7F506 5 Bytes  [ B6, EC, 77, 9E, 7C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 22                                                                             7CA7F50C 26 Bytes  CALL 7C9F3A7E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 3D                                                                             7CA7F527 18 Bytes  CALL 7C9F3A81 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 52                                                                             7CA7F53C 27 Bytes  [ 6A, 00, FF, 75, FC, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 6F                                                                             7CA7F559 54 Bytes  [ A1, 08, C5, BC, 7C, 53, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 11                                                                             7CA7FA04 32 Bytes  [ FF, F3, AB, 68, 08, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 32                                                                             7CA7FA25 6 Bytes  [ FF, 50, E8, 0E, F8, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 39                                                                             7CA7FA2C 5 Bytes  [ 8D, 85, D8, F7, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 3F                                                                             7CA7FA32 67 Bytes  [ 50, FF, 15, AC, 20, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 17                                                                        7CA7FA76 35 Bytes  [ FF, FF, 15, 78, 20, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 3B                                                                        7CA7FA9A 39 Bytes  [ C9, C2, 04, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 63                                                                        7CA7FAC2 11 Bytes  [ 00, 00, 8D, 85, F4, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 6F                                                                        7CA7FACE 25 Bytes  [ 15, E0, 19, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 89                                                                        7CA7FAE8 38 Bytes  [ 15, CC, 20, 9D, 7C, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 20                                                                        7CA7FC4A 10 Bytes  [ 75, 0C, FF, 75, 10, 53, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 2D                                                                        7CA7FC57 24 Bytes  [ F8, 56, FF, 15, 90, 1A, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 48                                                                        7CA7FC72 57 Bytes  [ 00, 74, 16, FF, B5, EC, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 82                                                                        7CA7FCAC 5 Bytes  [ 75, 08, E8, 1C, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 89                                                                        7CA7FCB3 88 Bytes  [ 5D, C2, 08, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconW + F                                                                           7CA7FD28 41 Bytes  [ 08, 57, 8B, 7D, 0C, 68, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconW + 39                                                                          7CA7FD52 53 Bytes  CALL 7CA7F54A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconA + 11                                                                                    7CA7FD88 56 Bytes  [ 5D, C2, 10, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconA + 4A                                                                                    7CA7FDC1 26 Bytes  [ FF, 8D, 85, E4, FB, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + 1                                                                         7CA7FDDC 13 Bytes  [ 45, F8, FF, B5, E0, FB, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + F                                                                         7CA7FDEA 163 Bytes  [ FF, 33, C0, 40, EB, 05, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + B3                                                                        7CA7FE8E 82 Bytes  [ 55, 8B, EC, 8B, 45, 14, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + 108                                                                       7CA7FEE3 41 Bytes  [ 8B, FF, 55, 8B, EC, 53, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 28                                                                          7CA7FF0D 104 Bytes  [ C0, 74, 1B, 8B, 4D, 14, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 91                                                                          7CA7FF76 165 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 137                                                                         7CA8001C 17 Bytes  [ 00, 2B, D7, 79, 02, F7, DA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 4                                                                              7CA8002E 78 Bytes  [ CF, 2B, CA, 8B, D1, 0F, AF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 53                                                                             7CA8007D 1 Byte  [ AF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 55                                                                             7CA8007F 102 Bytes  [ 0F, AF, C3, 33, D2, F7, F1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + BC                                                                             7CA800E6 150 Bytes  [ 7D, 18, 8B, 1D, 10, 11, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + 5D                                                                             7CA8017D 57 Bytes  [ 45, 1C, FF, 70, 08, FF, D3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + 97                                                                             7CA801B7 11 Bytes  [ 75, F0, FF, 75, 08, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + A3                                                                             7CA801C3 26 Bytes  [ 75, EC, FF, D6, FF, 75, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + BE                                                                             7CA801DE 51 Bytes  [ 50, 6A, 01, 6A, 00, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + F2                                                                             7CA80212 116 Bytes  [ D8, 53, FF, 75, 08, FF, D7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHelpShortcuts_RunDLL + 3C                                                                          7CA8032B 78 Bytes  [ 08, FF, 15, 24, 12, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 20                                                                              7CA8037A 181 Bytes  [ 76, 22, 6A, 00, FF, 75, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + D6                                                                              7CA80430 63 Bytes  [ 00, 3B, 4D, 10, 74, 1A, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 116                                                                             7CA80470 148 Bytes  [ 0C, 74, 0B, 46, 83, C0, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 1AB                                                                             7CA80505 18 Bytes  [ FF, 8B, 4D, 18, 33, FF, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 1BE                                                                             7CA80518 34 Bytes  [ 51, BE, 04, 01, 00, 00, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 16                                                                                7CA80763 81 Bytes  [ 8B, 8D, C4, FD, FF, FF, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 68                                                                                7CA807B5 6 Bytes  [ 00, 66, 83, BD, CE, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 6F                                                                                7CA807BC 21 Bytes  [ FF, 01, 66, 89, 9D, CC, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 85                                                                                7CA807D2 9 Bytes  [ 6B, C0, 0E, 83, C0, 06, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 8F                                                                                7CA807DC 16 Bytes  [ 15, 48, 19, 9D, 7C, 3B, C3, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + D                                                                                 7CA80828 65 Bytes  [ FF, A5, 83, C0, 06, 66, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 4F                                                                                7CA8086A 9 Bytes  [ F0, FD, FF, FF, 8B, BD, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 59                                                                                7CA80874 67 Bytes  [ 8B, 8D, DC, FD, FF, FF, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 9D                                                                                7CA808B8 32 Bytes  [ FF, 15, 4C, 19, 9D, 7C, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + BF                                                                                7CA808DA 29 Bytes  [ FF, B5, DC, FD, FF, FF, E9, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 14                                                                                     7CA80F1D 1 Byte  [ 66 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 16                                                                                     7CA80F1F 91 Bytes  [ B5, DC, FD, FF, FF, B9, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 72                                                                                     7CA80F7B 79 Bytes  [ DC, FD, FF, FF, 50, 56, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + C2                                                                                     7CA80FCB 128 Bytes  [ 55, 8B, EC, 33, C0, 39, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 143                                                                                    7CA8104C 16 Bytes  [ 75, 08, FF, 15, 90, 1F, 9D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 20                                                                                7CA81326 3 Bytes  [ C0, 74, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 24                                                                                7CA8132A 44 Bytes  [ 75, 14, 57, FF, 75, 0C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 54                                                                                7CA8135A 52 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 8A                                                                                7CA81390 4 Bytes  [ 50, 6A, 02, 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 8F                                                                                7CA81395 13 Bytes  CALL 7C9F7E45 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDriveA + 43                                                                                     7CA814C5 1 Byte  [ 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 5                                                                                      7CA814D1 48 Bytes  [ 83, EC, 34, 53, 56, 8B, 35, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 36                                                                                     7CA81502 21 Bytes  [ CC, 50, FF, 75, 0C, 89, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 4C                                                                                     7CA81518 32 Bytes  [ 75, 08, FF, 15, C8, 13, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 6D                                                                                     7CA81539 38 Bytes  [ 6A, 00, 6A, 00, 68, 04, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 94                                                                                     7CA81560 126 Bytes  CALL 7CA814CA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 8                                                                               7CA818BC 31 Bytes  [ 00, 00, 0D, 00, 00, 07, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 28                                                                              7CA818DC 95 Bytes  [ 7D, 08, 6A, 04, 57, FF, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 88                                                                              7CA8193C 35 Bytes  [ FF, 50, 8D, 85, 24, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + AC                                                                              7CA81960 58 Bytes  [ EB, 03, 83, 26, 00, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + E7                                                                              7CA8199B 25 Bytes  [ 15, 84, 1F, 9D, 7C, 8B, 4D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 18                                                                                     7CA82768 43 Bytes  [ 7D, 08, 89, 95, E0, FB, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 44                                                                                     7CA82794 13 Bytes  [ 03, C0, 89, 85, C8, FB, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 52                                                                                     7CA827A2 42 Bytes  [ FF, 2B, C7, 03, C3, D1, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 7D                                                                                     7CA827CD 9 Bytes  JMP 7CA82884 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 87                                                                                     7CA827D7 5 Bytes  [ FF, 8D, 85, F4, FD ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + 5B                                                                         7CA835CA 10 Bytes  [ 15, 0C, 13, 9D, 7C, E9, E1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + 66                                                                         7CA835D5 58 Bytes  [ 35, C8, 12, 9D, 7C, 6A, 0B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + A1                                                                         7CA83610 18 Bytes  [ 15, 1C, 11, 9D, 7C, 33, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + B4                                                                         7CA83623 8 Bytes  [ 76, 18, FF, 15, 18, 11, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + BD                                                                         7CA8362C 247 Bytes  CALL 7CA39AD3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLL + 28                                                                       7CA83724 168 Bytes  [ 56, 89, 07, FF, 15, 90, 1A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 4C                                                                      7CA837CD 2 Bytes  [ 75, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 4F                                                                      7CA837D0 3 Bytes  [ 45, F4, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 53                                                                      7CA837D4 8 Bytes  [ 75, F8, FF, 75, FC, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 5C                                                                      7CA837DD 8 Bytes  [ 75, 08, FF, 75, 18, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 66                                                                      7CA837E7 64 Bytes  [ 75, 2E, FF, D3, 83, F8, 7A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddFromPropSheetExtArray + 2                                                                       7CA83BA1 109 Bytes  [ 3C, 00, 00, 00, C7, 85, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 18                                                                  7CA83C0F 74 Bytes  [ F8, FF, 15, A0, 1A, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 63                                                                  7CA83C5A 78 Bytes  [ 80, 00, 00, 56, 89, 85, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + B2                                                                  7CA83CA9 7 Bytes  [ C7, 74, 38, 66, 39, 38, 74 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + BA                                                                  7CA83CB1 79 Bytes  CALL 7CA23E6B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 10B                                                                 7CA83D02 32 Bytes  CALL 7CACBA26 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 1                                                                        7CA83DD1 6 Bytes  [ 35, 8C, 1A, 9D, 7C, 53 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 8                                                                        7CA83DD8 2 Bytes  [ 77, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + B                                                                        7CA83DDB 184 Bytes  [ D6, 8D, 5C, 00, 02, 8D, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + C4                                                                       7CA83E94 84 Bytes  [ EC, 56, 57, FF, 75, 08, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 119                                                                      7CA83EE9 32 Bytes  [ FF, 8B, 45, 0C, BE, 08, 02, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryPoint + 5                                                                                   7CA83F4A 1 Byte  [ FB ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryPoint + 7                                                                                   7CA83F4C 118 Bytes  [ FF, 50, C7, 85, CC, F7, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 10                                                                                   7CA83FC3 9 Bytes  [ B5, C8, F7, FF, FF, 89, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 1A                                                                                   7CA83FCD 86 Bytes  CALL 7CAA134A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 71                                                                                   7CA84024 6 Bytes  [ FF, 50, 8D, 85, DC, F7 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 78                                                                                   7CA8402B 66 Bytes  CALL 7CA26C4E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + BB                                                                                   7CA8406E 2 Bytes  [ EC, FB ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 3F                                                                                 7CA84761 33 Bytes  [ FF, 75, FC, FF, 15, 90, 1A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 61                                                                                 7CA84783 3 Bytes  [ 55, 8B, EC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 65                                                                                 7CA84787 5 Bytes  JMP 7CA84641 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 6D                                                                                 7CA8478F 49 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 9F                                                                                 7CA847C1 60 Bytes  CALL 06A847C1 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 3E                                                                                   7CA8504F 49 Bytes  [ 55, 8B, EC, 81, EC, CC, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 70                                                                                   7CA85081 1 Byte  [ 40 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 74                                                                                   7CA85085 5 Bytes  [ 8D, 85, 50, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 7A                                                                                   7CA8508B 50 Bytes  [ 50, 6A, 09, 33, F6, 56, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + AD                                                                                   7CA850BE 22 Bytes  [ FF, FF, 15, 8C, 1B, 9D, 7C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 28                                                                                7CA859F5 112 Bytes  [ EB, 90, 66, 83, 7D, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 99                                                                                7CA85A66 109 Bytes  [ 8B, 75, 10, 83, E6, F0, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 107                                                                               7CA85AD4 175 Bytes  [ 75, 14, 56, FF, 75, 08, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 1B7                                                                               7CA85B84 66 Bytes  [ 15, 90, 1A, 9D, 7C, 8B, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 1FA                                                                               7CA85BC7 21 Bytes  [ 15, 64, 13, 9D, 7C, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesW + 47                                                                                   7CA876B3 20 Bytes  [ C6, 8B, 75, 10, 74, 11, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesW + 5C                                                                                   7CA876C8 209 Bytes  [ 50, 10, 53, FF, 15, 68, 1A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + 85                                                                                   7CA8779A 14 Bytes  [ 53, 18, FF, 75, F8, FF, D7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + 94                                                                                   7CA877A9 45 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + C2                                                                                   7CA877D7 47 Bytes  [ 15, 90, 1A, 9D, 7C, 83, 26, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 1                                                                                         7CA87807 14 Bytes  [ 35, 2C, 13, 9D, 7C, 6A, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 11                                                                                        7CA87817 14 Bytes  [ 10, FF, D6, 6A, 00, 50, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 20                                                                                        7CA87826 28 Bytes  [ D6, 85, C0, 5E, 74, 0F, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 3E                                                                                        7CA87844 3 Bytes  [ 8B, FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 1                                                                                         7CA87848 29 Bytes  [ EC, 51, 83, 65, FC, 00, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 1F                                                                                        7CA87866 23 Bytes  [ 85, C0, 7C, 20, 8D, 45, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 37                                                                                        7CA8787E 18 Bytes  [ 8B, 45, FC, F7, D8, 1B, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpW + E                                                                                         7CA87891 30 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpW + 2D                                                                                        7CA878B0 122 Bytes  CALL 7CBAAC2B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpA + 22                                                                                        7CA8792B 4 Bytes  [ EB, 03, 83, 27 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpA + 27                                                                                        7CA87930 128 Bytes  [ 53, 6A, 3C, 8D, 5E, 3C, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIW + 30                                                                                       7CA879B1 99 Bytes  [ AA, 68, C8, 7D, 9E, 7C, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 27                                                                                       7CA87A15 24 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 40                                                                                       7CA87A2E 40 Bytes  [ 08, 57, 68, 51, 33, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 69                                                                                       7CA87A57 16 Bytes  [ FF, D7, C7, 85, 4C, FA, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCpyW + 2                                                                                         7CA87A68 96 Bytes  [ FF, 0F, BF, 00, 68, 50, A6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCpyA + 18                                                                                        7CA87AC9 62 Bytes  [ FF, 74, 48, 8B, 85, 4C, FA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrW + 7                                                                                         7CA87B08 78 Bytes  [ 33, 00, 00, FF, 76, 34, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrW + 56                                                                                        7CA87B57 78 Bytes  [ 06, 43, 83, FB, 0C, 72, E3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 38                                                                                        7CA87BA6 1 Byte  [ 17 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 3A                                                                                        7CA87BA8 3 Bytes  [ B5, 44, FA ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 3E                                                                                        7CA87BAC 50 Bytes  [ FF, 8D, 85, 50, FA, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 71                                                                                        7CA87BDF 19 Bytes  [ 50, 68, 9A, 01, 00, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 85                                                                                        7CA87BF3 9 Bytes  [ 8D, 85, 3C, FA, FF, FF, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 1B                                                                               7CA87C4B 56 Bytes  [ BE, B8, 00, 00, 00, 01, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 54                                                                               7CA87C84 20 Bytes  [ F8, FF, 89, 85, 38, FA, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 69                                                                               7CA87C99 69 Bytes  [ A5, 4C, FA, FF, FF, 00, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirW + 35                                                                                      7CA87CDF 112 Bytes  [ FF, 8B, 9D, 34, FA, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 4                                                                                       7CA87D50 33 Bytes  [ 8E, BC, 00, 00, 00, 66, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 27                                                                                      7CA87D73 48 Bytes  [ D7, 6A, 00, 6A, 00, 68, 86, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 58                                                                                      7CA87DA4 13 Bytes  CALL 7C9F0920 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 66                                                                                      7CA87DB2 13 Bytes  [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + B                                                                                    7CA87DC1 24 Bytes  CALL 7CA87894 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 24                                                                                   7CA87DDA 217 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + FE                                                                                   7CA87EB4 25 Bytes  [ 5C, 12, 00, 00, 52, 33, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 118                                                                                  7CA87ECE 27 Bytes  [ FF, 55, 8B, EC, 81, EC, D4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 134                                                                                  7CA87EEA 7 Bytes  [ 15, 44, 1A, 9D, 7C, 83, F8 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirA + 1F                                                                                   7CA87FB8 29 Bytes  [ A1, 08, C5, BC, 7C, 53, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirA + 3D                                                                                   7CA87FD6 49 Bytes  [ 85, C0, 0F, 85, CF, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetCurDrive + 16                                                                                  7CA88008 75 Bytes  [ FF, 89, 85, C4, FE, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheSetCurDrive + 3C                                                                                  7CA88054 22 Bytes  [ FF, 50, 56, FF, 15, F8, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 2                                                                                     7CA8806B 12 Bytes  [ 40, 8D, 85, B8, FE, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + F                                                                                     7CA88078 16 Bytes  [ FF, 10, 20, 9E, 7C, 89, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 20                                                                                    7CA88089 34 Bytes  [ 85, F4, FE, FF, FF, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 43                                                                                    7CA880AC 26 Bytes  [ 05, B8, 05, 00, 07, 80, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 5E                                                                                    7CA880C7 23 Bytes  [ FF, 55, 8B, EC, 51, 8D, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 64                                                                                    7CA8817F 47 Bytes  [ FF, 50, FF, 15, 8C, 1A, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 95                                                                                    7CA881B0 3 Bytes  [ B5, 9C, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 99                                                                                    7CA881B4 22 Bytes  CALL 7C9F3900 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + B1                                                                                    7CA881CC 1 Byte  [ 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 7                                                                                     7CA881DA 1 Byte  [ 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 10                                                                                    7CA881E3 1 Byte  [ 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 12                                                                                    7CA881E5 8 Bytes  [ 75, 0C, 68, 00, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 1B                                                                                    7CA881EE 11 Bytes  [ FC, 8D, 85, FC, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 27                                                                                    7CA881FA 5 Bytes  [ 35, 64, C5, BC, 7C ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 16                                                                                 7CA882E6 103 Bytes  [ 75, 1C, 0F, B7, 45, 10, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 7E                                                                                 7CA8834E 5 Bytes  [ FF, 0F, 84, 15, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 84                                                                                 7CA88354 19 Bytes  [ 00, 56, 8B, 75, 10, 3B, F2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 98                                                                                 7CA88368 48 Bytes  [ 00, 00, 81, FE, C7, 04, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + C9                                                                                 7CA88399 11 Bytes  [ FF, BF, 0C, 03, 00, 00, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 5                                                                                  7CA88558 54 Bytes  [ 5D, EB, AD, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 3C                                                                                 7CA8858F 38 Bytes  [ 85, C0, 0F, 85, 86, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 63                                                                                 7CA885B6 5 Bytes  [ 01, 00, 00, 00, 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 69                                                                                 7CA885BC 167 Bytes  [ 75, 0C, FF, 15, 8C, 1A, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 111                                                                                7CA88664 59 Bytes  [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 25                                                                       7CA896CB 9 Bytes  [ 50, FF, 36, 66, 89, BD, F0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 2F                                                                       7CA896D5 2 Bytes  [ 66, C7 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 32                                                                       7CA896D8 2 Bytes  [ F2, EF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 36                                                                       7CA896DC 82 Bytes  [ 00, 10, FF, 15, CC, 10, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 89                                                                       7CA8972F 34 Bytes  [ D7, 85, C0, 74, 13, 68, B0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + 5                                                                                   7CA89AD7 7 Bytes  [ 00, 83, BD, F0, FD, FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + D                                                                                   7CA89ADF 22 Bytes  [ 74, 7C, C6, 83, FF, 07, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + 24                                                                                  7CA89AF6 153 Bytes  [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + BE                                                                                  7CA89B90 13 Bytes  [ 00, 00, FF, B5, E0, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + CC                                                                                  7CA89B9E 28 Bytes  [ FF, D6, 85, C0, 0F, 84, 30, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 1                                                                           7CA8EF3A 95 Bytes  CALL 7C9F091C C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 61                                                                          7CA8EF9A 143 Bytes  [ 50, 89, 9D, C0, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + F2                                                                          7CA8F02B 72 Bytes  [ FF, B5, D0, FD, FF, FF, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 13B                                                                         7CA8F074 34 Bytes  [ 00, FF, 15, 20, 1A, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 15E                                                                         7CA8F097 11 Bytes  [ B0, FD, FF, FF, 50, 53, 68, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 25                                                                            7CA8F67C 79 Bytes  [ 8B, C6, 5E, 5D, C2, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 75                                                                            7CA8F6CC 4 Bytes  [ 57, 56, E8, 51 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 7B                                                                            7CA8F6D2 19 Bytes  [ FF, 8B, F0, 3B, F7, 75, D1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 8F                                                                            7CA8F6E6 81 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + E1                                                                            7CA8F738 26 Bytes  [ 55, 8B, EC, 83, 7D, 0C, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 65                                                                            7CA8FF3B 161 Bytes  [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 107                                                                           7CA8FFDD 31 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 127                                                                           7CA8FFFD 49 Bytes  [ 3B, FB, 0F, 9C, C1, 33, D2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 159                                                                           7CA9002F 72 Bytes  [ 15, 84, 1A, 9D, 7C, EB, 1F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 1A2                                                                           7CA90078 42 Bytes  [ FF, FF, 8B, 46, 1C, 66, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 11B                                                                          7CA904EF 3 Bytes  [ 15, 5C, 20 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 11F                                                                          7CA904F3 34 Bytes  [ 7C, 85, C0, 74, 10, 83, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 143                                                                          7CA90517 34 Bytes  [ C9, C3, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 166                                                                          7CA9053A 11 Bytes  [ 51, 8D, 8D, EC, FB, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 172                                                                          7CA90546 18 Bytes  [ 00, 53, 33, FF, 89, 45, FC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesW + 6                                                                                 7CA9889B 81 Bytes  [ 4D, B8, 8B, 40, 04, C1, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 1C                                                                                7CA988ED 9 Bytes  [ 75, B0, 89, 75, B4, FF, D3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 26                                                                                7CA988F7 84 Bytes  [ 21, 8B, 45, AC, 8B, 48, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 7B                                                                                7CA9894C 96 Bytes  [ 89, 48, 22, 8D, 45, B4, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 25                                                                                 7CA989AD 35 Bytes  [ 75, B0, C7, 45, B4, 40, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 49                                                                                 7CA989D1 27 Bytes  [ 83, 60, 02, 00, 6A, 04, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 65                                                                                 7CA989ED 7 Bytes  [ 75, B4, FF, D3, 85, C0, 75 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 6D                                                                                 7CA989F5 172 Bytes  [ 8B, 45, AC, 8B, 40, 04, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 11A                                                                                7CA98AA2 60 Bytes  [ C9, C2, 04, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + 11                                                                                 7CA98B4C 147 Bytes  [ 56, 8B, 35, B0, 1A, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + A5                                                                                 7CA98BE0 35 Bytes  [ D6, 8B, 47, 04, 8B, 40, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + C9                                                                                 7CA98C04 40 Bytes  [ 45, B8, 8D, 45, B8, 50, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + F2                                                                                 7CA98C2D 10 Bytes  [ 6A, 00, 68, 90, 1B, 9E, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + FD                                                                                 7CA98C38 6 Bytes  [ 4D, B8, FF, D6, 8B, 47 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + 16                                                                                 7CA98F05 17 Bytes  [ 00, 80, 80, 80, 00, 8B, 42, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + 28                                                                                 7CA98F17 128 Bytes  [ 8B, 42, 04, C7, 80, B4, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + A9                                                                                 7CA98F98 9 Bytes  [ EC, 20, FF, 75, 0C, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + B4                                                                                 7CA98FA3 2 Bytes  [ D0, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + B9                                                                                 7CA98FA8 61 Bytes  [ 45, 08, 83, 65, F0, 00, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 10                                                                                   7CA9A9B0 40 Bytes  [ 50, FF, 15, 5C, 13, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 39                                                                                   7CA9A9D9 1 Byte  [ 6A ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 3B                                                                                   7CA9A9DB 33 Bytes  [ FF, 15, 2C, 13, 9D, 7C, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 5D                                                                                   7CA9A9FD 70 Bytes  [ 15, 54, 13, 9D, 7C, EB, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + A4                                                                                   7CA9AA44 43 Bytes  [ 76, 10, FF, 15, E0, 12, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 16                                                                                  7CA9AA70 16 Bytes  [ 10, 8D, 8E, 24, 02, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 27                                                                                  7CA9AA81 62 Bytes  [ D7, F7, D8, 1B, C0, 40, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 66                                                                                  7CA9AAC0 30 Bytes  [ 75, 08, 6A, 00, FF, 35, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 86                                                                                  7CA9AAE0 31 Bytes  [ 68, 8C, CE, 9D, 7C, BB, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + A6                                                                                  7CA9AB00 11 Bytes  [ 0D, 64, C5, BC, 7C, 89, 4D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 12                                                                                 7CA9BA16 24 Bytes  [ B5, E0, FD, FF, FF, 89, BD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 2B                                                                                 7CA9BA2F 12 Bytes  [ FF, 57, FF, 15, 90, 1A, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 39                                                                                 7CA9BA3D 6 Bytes  [ 00, 5F, 5E, 5B, 7C, 06 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 40                                                                                 7CA9BA44 38 Bytes  [ 15, E4, C0, BC, 7C, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 67                                                                                 7CA9BA6B 26 Bytes  [ 8B, 5D, 08, 56, 8B, 75, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 1F                                                                        7CA9EEEC 5 Bytes  [ 53, 8D, 95, EC, DC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 25                                                                        7CA9EEF2 29 Bytes  [ FF, 52, FF, B5, E0, DC, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 43                                                                        7CA9EF10 10 Bytes  [ 83, 3E, 00, 75, A2, 8B, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 4E                                                                        7CA9EF1B 22 Bytes  [ 8B, 08, 50, FF, 51, 08, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 65                                                                        7CA9EF32 45 Bytes  [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + 36                                                                  7CA9F2ED 132 Bytes  [ C2, 08, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + BC                                                                  7CA9F373 5 Bytes  [ FF, 75, 0C, 6A, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + C2                                                                  7CA9F379 6 Bytes  [ 75, 08, E8, 28, 1D, F9 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + C9                                                                  7CA9F380 15 Bytes  [ 8B, F0, 8B, 45, 08, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + D9                                                                  7CA9F390 60 Bytes  [ C6, 5E, 5D, C2, 0C, 00, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 21                                                                   7CA9F67C 100 Bytes  [ 14, 8B, C1, 75, 05, 39, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 86                                                                   7CA9F6E1 2 Bytes  [ 85, D7 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 8B                                                                   7CA9F6E6 13 Bytes  [ 8D, 85, FC, FB, FF, FF, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 99                                                                   7CA9F6F4 21 Bytes  JMP 7CA9F7BA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + AF                                                                   7CA9F70A 66 Bytes  [ 11, B5, AC, FB, FF, FF, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA                                                                               7CAA17AE 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + 4                                                                           7CAA17B2 156 Bytes  [ FF, 55, 8B, EC, 56, 8B, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + A1                                                                          7CAA184F 47 Bytes  [ 15, 8C, 1A, 9D, 7C, 8B, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + D1                                                                          7CAA187F 150 Bytes  [ 08, 50, FF, 51, 04, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + 168                                                                         7CAA1916 33 Bytes  [ 89, 45, FC, 8B, 45, 10, 89, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 1C                                                                           7CAA1B03 39 Bytes  [ F8, 01, 00, 00, 00, E8, 91, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 44                                                                           7CAA1B2B 2 Bytes  [ 84, 63 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 49                                                                           7CAA1B30 28 Bytes  [ 8B, 0F, 80, E1, 01, F6, D9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 66                                                                           7CAA1B4D 36 Bytes  [ 51, 53, 6A, 00, 68, 6C, 78, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 8B                                                                           7CAA1B72 29 Bytes  [ 75, FC, FF, D6, 8B, 07, F7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 11                                                                           7CAA1D0C 199 Bytes  [ EC, 56, 33, F6, 39, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + D9                                                                           7CAA1DD4 10 Bytes  CALL D026BAEB 
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + E4                                                                           7CAA1DDF 79 Bytes  [ FF, 50, 8D, 85, FC, DF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 135                                                                          7CAA1E30 11 Bytes  [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 141                                                                          7CAA1E3C 35 Bytes  [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 27                                                                        7CAA21AA 54 Bytes  [ 8B, 45, 18, 57, 89, 85, E0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 5E                                                                        7CAA21E1 12 Bytes  [ FF, 89, BD, BC, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 6B                                                                        7CAA21EE 11 Bytes  [ 89, BD, C4, FD, FF, FF, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 77                                                                        7CAA21FA 16 Bytes  [ 89, 85, CC, FD, FF, FF, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 88                                                                        7CAA220B 38 Bytes  [ FF, 74, 51, 53, 68, 04, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 2A                                                                                   7CAA50A7 38 Bytes  [ D3, 6A, 01, 68, 82, 70, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 51                                                                                   7CAA50CE 11 Bytes  [ D3, 68, B4, 43, 9D, 7C, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 5D                                                                                   7CAA50DA 10 Bytes  [ 76, 30, FF, D7, 50, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 68                                                                                   7CAA50E5 104 Bytes  [ 83, 66, 04, 00, 5F, C7, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + D1                                                                                   7CAA514E 8 Bytes  [ 15, D4, 12, 9D, 7C, 8B, F8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 2                                                                                7CAA57C9 37 Bytes  [ 51, 05, 20, 70, 00, 00, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 28                                                                               7CAA57EF 12 Bytes  JMP 7CAA5888 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 35                                                                               7CAA57FC 28 Bytes  CALL 7CAA4C1E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 54                                                                               7CAA581B 100 Bytes  [ FF, B5, D0, FD, FF, FF, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + B9                                                                               7CAA5880 20 Bytes  [ 0F, AF, 85, D8, FD, FF, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create + 36                                                                           7CAA6F5B 143 Bytes  [ 15, 9D, 7C, 6A, 00, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 27                                                                          7CAA6FEB 22 Bytes  [ 35, EC, 14, 9D, 7C, 6A, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 3F                                                                          7CAA7003 1 Byte  [ 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 41                                                                          7CAA7005 48 Bytes  [ D6, 83, C7, FD, 6A, 00, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 72                                                                          7CAA7036 21 Bytes  [ 15, 04, 13, 9D, 7C, 8B, 1D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 88                                                                          7CAA704C 89 Bytes  [ FF, FF, 8B, F8, 85, FF, 7C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll                                                                                       7CAB22D7 22 Bytes  [ 1A, 9D, 7C, 33, C0, 5E, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 17                                                                                  7CAB22EE 29 Bytes  [ 85, C0, 74, 14, 81, 78, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 35                                                                                  7CAB230C 6 Bytes  [ 90, 90, 90, 90, 90, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 3C                                                                                  7CAB2313 30 Bytes  [ 55, 8B, EC, 53, 56, 8B, 35, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 5B                                                                                  7CAB2332 142 Bytes  [ 00, 57, FF, D6, 53, 68, 2E, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 1                                                                                  7CABB59D 32 Bytes  [ 55, F8, D1, F8, 03, D1, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 22                                                                                 7CABB5BE 45 Bytes  [ CE, 2B, C8, 89, 4D, FC, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 50                                                                                 7CABB5EC 78 Bytes  [ FF, 39, 7D, 0C, 8B, F0, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 6                                                                                 7CABB63B 25 Bytes  [ FF, 15, 34, 12, 9D, 7C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 21                                                                                7CABB656 75 Bytes  CALL 7CA82C5A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 6D                                                                                7CABB6A2 9 Bytes  [ D3, FF, 75, E4, FF, 75, F4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 77                                                                                7CABB6AC 60 Bytes  [ 75, F4, FF, 15, 44, 12, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragLeave + 19                                                                                   7CABB6E9 21 Bytes  [ FF, 47, 8B, C7, 5F, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragLeave + 31                                                                                   7CABB701 51 Bytes  [ 8D, 45, 0C, 50, 8D, 45, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 4                                                                                     7CABB735 10 Bytes  [ 35, 40, 12, 9D, 7C, 74, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + F                                                                                     7CABB740 83 Bytes  [ D6, 83, 7D, 0C, 00, 74, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 63                                                                                    7CABB794 8 Bytes  [ EC, 53, 57, 8B, 7D, 08, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 6C                                                                                    7CABB79D 31 Bytes  [ 3B, F8, 8B, D9, 75, 0C, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 8C                                                                                    7CABB7BD 77 Bytes  [ 86, 1C, D6, 9D, 7C, FF, B6, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 3B                                                                                      7CABE7F7 67 Bytes  [ FF, 6A, 50, 50, FF, D6, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 80                                                                                      7CABE83C 4 Bytes  [ B5, B8, FE, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 86                                                                                      7CABE842 47 Bytes  [ 15, A0, 1A, 9D, 7C, 33, DB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + B6                                                                                      7CABE872 1 Byte  [ 73 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + B8                                                                                      7CABE874 25 Bytes  [ 70, 00, 31, 00, 72, 00, 65, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 56                                                                               7CAC19F0 25 Bytes  [ 33, C0, 83, FB, 02, 0F, 95, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 70                                                                               7CAC1A0A 318 Bytes  [ 57, FF, 15, 20, 13, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1B0                                                                              7CAC1B4A 58 Bytes  [ 50, 8D, 85, D4, F5, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1EB                                                                              7CAC1B85 3 Bytes  [ 85, EC, FB ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1F0                                                                              7CAC1B8A 6 Bytes  [ 50, 8D, 85, DC, F7, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 1                                                                                    7CAC1F3A 68 Bytes  [ 45, 14, 68, F0, 0F, AC, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 46                                                                                   7CAC1F7F 47 Bytes  JMP E70A949F 
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 76                                                                                   7CAC1FAF 43 Bytes  [ 15, 2C, 13, 9D, 7C, EB, 2C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + A2                                                                                   7CAC1FDB 57 Bytes  [ 10, FF, 15, E4, 13, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + DC                                                                                   7CAC2015 57 Bytes  [ 12, 00, 00, 5B, 38, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SignalFileOpen + C9                                                                                  7CAC27B2 14 Bytes  [ 15, A0, 1A, 9D, 7C, 89, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SignalFileOpen + D8                                                                                  7CAC27C1 16 Bytes  [ 80, 6A, 40, 8D, 85, 64, FE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 2                                                                              7CAC27D2 53 Bytes  [ B0, 60, 9D, 9E, 7C, C7, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 38                                                                             7CAC2808 14 Bytes  [ 85, 54, FC, FF, FF, 50, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 47                                                                             7CAC2817 21 Bytes  [ 6A, 02, 6A, 00, 8D, 85, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 5D                                                                             7CAC282D 164 Bytes  [ B4, 00, 00, 00, 68, A0, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExW + 59                                                                             7CAC28D2 90 Bytes  [ FE, FF, FF, EB, DB, 8D, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + B                                                                                7CAC292D 20 Bytes  [ FF, 50, 8D, 85, 5C, FC, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + 20                                                                               7CAC2942 2 Bytes  [ 50, 53 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + 23                                                                               7CAC2945 41 Bytes  [ 15, BC, 1F, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteW + 1A                                                                               7CAC296F 10 Bytes  CALL 7CA9EA3F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteW + 25                                                                               7CAC297A 14 Bytes  [ 83, FE, 50, 0F, 82, 78, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + 1                                                                                    7CAC2989 108 Bytes  [ 4D, FC, 5F, 5E, 5B, E8, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + 6E                                                                                   7CAC29F6 96 Bytes  [ FF, 55, 8B, EC, 8D, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + CF                                                                                   7CAC2A57 7 Bytes  [ F8, 66, 8B, 07, 66, 85, C0 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + D7                                                                                   7CAC2A5F 21 Bytes  JMP 7CAC2B4B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + ED                                                                                   7CAC2A75 67 Bytes  [ 74, 02, 47, 47, 56, 8B, 35, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 27                                                                           7CAC3F69 6 Bytes  [ FF, 50, 8D, 85, F4, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 2E                                                                           7CAC3F70 9 Bytes  [ FF, 50, 53, FF, 15, 34, 13, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 38                                                                           7CAC3F7A 78 Bytes  [ 4D, FC, 5F, 5E, 5B, E8, 9C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 87                                                                           7CAC3FC9 6 Bytes  [ 66, 89, 85, E4, F0, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 8E                                                                           7CAC3FD0 5 Bytes  [ 33, C0, 53, 56, 57 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 11                                                                                      7CAC4331 67 Bytes  [ 50, 8D, 45, FC, 2B, 85, 78, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 55                                                                                      7CAC4375 36 Bytes  [ 15, 34, 21, 9D, 7C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 7B                                                                                      7CAC439B 14 Bytes  [ 3D, 3C, 20, 9D, 7C, 6A, 5C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 8A                                                                                      7CAC43AA 28 Bytes  [ D7, 85, C0, 75, 0F, 6A, 2F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + A7                                                                                      7CAC43C7 41 Bytes  [ D7, 50, 8D, 85, EC, FB, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 9                                                                                7CAC4588 26 Bytes  [ 50, FF, 51, 28, EB, 06, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 24                                                                               7CAC45A3 59 Bytes  [ 50, 56, FF, B5, 4C, F1, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 60                                                                               7CAC45DF 16 Bytes  [ 85, 50, F1, FF, FF, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 71                                                                               7CAC45F0 16 Bytes  [ FF, 50, FF, B5, 6C, F1, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 82                                                                               7CAC4601 61 Bytes  [ B5, 68, F1, FF, FF, E8, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 29                                                                       7CAC66ED 2 Bytes  [ 55, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 2C                                                                       7CAC66F0 46 Bytes  [ 4D, DC, 5B, F6, 46, 20, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 5B                                                                       7CAC671F 2 Bytes  [ 35, F9 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 5E                                                                       7CAC6722 40 Bytes  [ FF, 85, C0, 8B, 4D, DC, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 87                                                                       7CAC674B 25 Bytes  [ 45, D8, 33, D2, 39, 55, 08, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 46                                                                             7CAC7A33 20 Bytes  [ 15, AC, 1A, 9D, 7C, FF, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 5C                                                                             7CAC7A49 66 Bytes  [ 00, 80, 0F, 85, 94, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 9F                                                                             7CAC7A8C 69 Bytes  [ FF, 50, 8B, 45, 08, 33, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + E5                                                                             7CAC7AD2 12 Bytes  [ D3, 89, 85, D4, FB, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + F2                                                                             7CAC7ADF 16 Bytes  [ FF, 15, A0, 1A, 9D, 7C, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 15                                                                     7CAC7FC9 41 Bytes  [ 76, 08, 57, FF, B5, F0, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 3F                                                                     7CAC7FF3 16 Bytes  [ FF, 50, 68, 00, 80, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 50                                                                     7CAC8004 14 Bytes  [ 0D, FF, B5, EC, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 5F                                                                     7CAC8013 1 Byte  [ 76 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 61                                                                     7CAC8015 4 Bytes  [ FF, B5, F0, FD ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 29                                                                                  7CAC80BE 14 Bytes  CALL 7C9F9620 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 38                                                                                  7CAC80CD 5 Bytes  [ 8D, 85, F4, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 3E                                                                                  7CAC80D3 33 Bytes  [ 50, FF, 15, 6C, 1F, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 60                                                                                  7CAC80F5 17 Bytes  [ 15, 7C, 20, 9D, 7C, 39, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 72                                                                                  7CAC8107 205 Bytes  [ 15, 8C, 1A, 9D, 7C, 8B, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 1                                                                                   7CAC81D5 72 Bytes  [ 45, 10, 89, 85, EC, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 4A                                                                                  7CAC821E 24 Bytes  [ 00, F6, 46, 11, 01, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 63                                                                                  7CAC8237 60 Bytes  [ 40, 00, 00, 6A, 00, 56, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + A0                                                                                  7CAC8274 16 Bytes  CALL 7CAC7F52 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + B1                                                                                  7CAC8285 38 Bytes  [ FF, D7, 50, 6A, 40, 68, 32, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 15                                                                            7CACF1E1 61 Bytes  [ EB, C4, C7, 45, FC, 0E, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 53                                                                            7CACF21F 5 Bytes  [ 57, 8D, 45, FC, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 59                                                                            7CACF225 26 Bytes  CALL 7CACB6FC C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 74                                                                            7CACF240 146 Bytes  [ FF, 8B, F0, 85, F6, 7C, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 107                                                                           7CACF2D3 136 Bytes  [ 74, 08, 2B, C1, 0F, 85, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 79                                                                                7CACF4C4 23 Bytes  [ 51, 0C, 8B, D8, 3B, DE, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 91                                                                                7CACF4DC 107 Bytes  [ 75, 0C, FF, 15, 88, 1E, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + FD                                                                                7CACF548 6 Bytes  JMP 7CACF63E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 104                                                                               7CACF54F 61 Bytes  [ 34, 8D, A0, AF, A6, 7C, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 142                                                                               7CACF58D 8 Bytes  [ F9, 0A, 0F, 8C, A9, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenFolderAndSelectItems + 7B                                                                      7CACF885 28 Bytes  [ 7C, 0E, 8B, 4D, FC, F7, D9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem                                                                                    7CACF8A2 7 Bytes  [ 90, 90, 90, 90, 8B, FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 8                                                                                7CACF8AA 29 Bytes  [ EC, 51, 83, 65, FC, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 26                                                                               7CACF8C8 2 Bytes  [ 4D, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 29                                                                               7CACF8CB 44 Bytes  [ D9, 1B, C9, 83, E1, FE, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 56                                                                               7CACF8F8 47 Bytes  [ 75, 08, 6A, 77, 6A, 06, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 9                                                                         7CACFA17 18 Bytes  [ 59, 8B, 55, 14, 89, 0A, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 1C                                                                        7CACFA2A 74 Bytes  [ EC, 51, 83, 65, FC, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 67                                                                        7CACFA75 66 Bytes  [ 75, 0C, FF, 75, 08, 6A, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + AA                                                                        7CACFAB8 79 Bytes  [ 75, 08, 6A, 02, 6A, 0A, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + FA                                                                        7CACFB08 63 Bytes  [ 4D, FC, F7, D9, 1B, C9, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 14                                                                                 7CAD0C5F 114 Bytes  [ 8D, 85, 54, FD, FF, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 87                                                                                 7CAD0CD2 4 Bytes  [ 8D, 85, 4C, FB ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 8C                                                                                 7CAD0CD7 36 Bytes  [ FF, 50, FF, 15, D8, 19, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + B1                                                                                 7CAD0CFC 76 Bytes  [ FF, 5F, 5E, 8B, 4D, FC, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + FE                                                                                 7CAD0D49 5 Bytes  [ FF, 89, 9D, D0, F9 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnableServiceObject + 2                                                                            7CAD0DBD 100 Bytes  [ D6, 8D, 85, F4, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 30                                                                           7CAD0E22 16 Bytes  [ FF, 50, FF, 15, 60, 1F, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 41                                                                           7CAD0E33 24 Bytes  [ 0F, 84, 33, 01, 00, 00, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 5A                                                                           7CAD0E4C 12 Bytes  [ FF, 50, FF, B5, CC, F9, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 67                                                                           7CAD0E59 50 Bytes  [ FF, 50, FF, D3, FF, B5, D0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 9B                                                                           7CAD0E8D 15 Bytes  CALL 7CA1EA16 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 17                                                                              7CAD3DA2 94 Bytes  [ C1, C7, 00, B0, 27, 9E, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 76                                                                              7CAD3E01 12 Bytes  [ 50, 68, 00, 80, 00, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 83                                                                              7CAD3E0E 78 Bytes  [ B5, F0, FD, FF, FF, E8, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + D3                                                                              7CAD3E5E 4 Bytes  [ 08, 50, FF, 51 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + D8                                                                              7CAD3E63 142 Bytes  [ 8B, 4D, FC, 33, C0, 85, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 6D                                                                               7CAD3EF2 11 Bytes  CALL 7CA0E665 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 79                                                                               7CAD3EFE 18 Bytes  [ 1D, D4, 12, 9D, 7C, 89, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 8C                                                                               7CAD3F11 12 Bytes  [ 50, 68, 44, 37, 00, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 99                                                                               7CAD3F1E 25 Bytes  [ 15, E4, 12, 9D, 7C, 83, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + B3                                                                               7CAD3F38 143 Bytes  [ 15, 54, 13, 9D, 7C, FF, 37, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WOWShellExecute + 2F                                                                                 7CAD5268 78 Bytes  [ 59, 8B, C6, 5E, 5D, C2, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WOWShellExecute + 7E                                                                                 7CAD52B7 315 Bytes  [ 51, 30, 8B, 46, 10, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLL + 24                                                                                7CAD53F3 126 Bytes  [ EC, 10, 00, 00, 00, E8, F1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 3D                                                                               7CAD5472 12 Bytes  [ 50, 0C, 8B, F0, 85, F6, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 4A                                                                               7CAD547F 30 Bytes  CALL 7CAD5121 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 69                                                                               7CAD549E 2 Bytes  [ 08, 53 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 6C                                                                               7CAD54A1 4 Bytes  [ 5D, 18, 53, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 71                                                                               7CAD54A6 17 Bytes  [ 14, 6A, 00, 57, 50, FF, 51, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 23                                                                          7CAD6018 41 Bytes  [ 75, FC, FF, 15, 58, 19, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 4D                                                                          7CAD6042 46 Bytes  [ 15, 68, 13, 9D, 7C, 56, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 7C                                                                          7CAD6071 15 Bytes  [ 00, 75, 0B, 53, FF, 15, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 8D                                                                          7CAD6082 22 Bytes  [ FF, 75, 10, 68, 13, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + A4                                                                          7CAD6099 328 Bytes  [ 7D, 08, 00, 74, 30, 6A, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + 28                                                                       7CAD76F3 79 Bytes  CALL 7CA31BC1 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + 78                                                                       7CAD7743 48 Bytes  [ FF, FF, 15, A0, 1A, 9D, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + AA                                                                       7CAD7775 24 Bytes  [ 45, FC, 8B, 45, 0C, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + C3                                                                       7CAD778E 14 Bytes  [ FD, FF, FF, 8D, 5E, F0, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + D2                                                                       7CAD779D 48 Bytes  [ 89, BD, DC, FD, FF, FF, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 2D                                                                       7CAD7BA0 9 Bytes  [ F4, F9, FF, FF, 50, E8, A9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 37                                                                       7CAD7BAA 10 Bytes  [ F7, D8, 1B, C0, 83, E0, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 42                                                                       7CAD7BB5 40 Bytes  [ 00, 50, FF, 35, 64, C5, BC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 6B                                                                       7CAD7BDE 9 Bytes  [ 83, C4, 10, EB, 31, 8B, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 75                                                                       7CAD7BE8 18 Bytes  [ FF, BB, 00, 01, 00, 00, 53, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 2                                                                             7CAD98C0 93 Bytes  [ 5E, 5D, C2, 08, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 60                                                                            7CAD991E 45 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 8E                                                                            7CAD994C 44 Bytes  CALL 7C9F3900 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + BB                                                                            7CAD9979 36 Bytes  [ 10, 89, 06, 74, 46, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + E0                                                                            7CAD999E 256 Bytes  [ FF, FF, 85, C0, 74, 0A, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 19                                                                                     7CADAF35 27 Bytes  [ 76, 20, 8B, 06, 57, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 35                                                                                     7CADAF51 7 Bytes  [ 51, 1C, 85, C0, 7C, E7, 33 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 3D                                                                                     7CADAF59 171 Bytes  [ 39, 7D, F8, 7E, E0, 8B, 46, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + EA                                                                                     7CADB006 6 Bytes  [ 0F, 84, C3, 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + F1                                                                                     7CADB00D 11 Bytes  [ 8D, F0, FD, FF, FF, 3B, BD, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 2                                                                      7CADE6DC 122 Bytes  [ 51, 40, 8B, F0, 3B, F7, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 7D                                                                     7CADE757 10 Bytes  [ 5C, FF, FF, FF, 3B, F7, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 89                                                                     7CADE763 8 Bytes  [ EB, 07, 66, 8B, 85, 5C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 92                                                                     7CADE76C 29 Bytes  [ 68, 00, 04, 00, 00, 57, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + B0                                                                     7CADE78A 10 Bytes  [ 1B, C0, 23, C1, 50, 68, A0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + 2                                                                           7CAE04BC 37 Bytes  [ 75, 10, 8B, 08, FF, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + 28                                                                          7CAE04E2 130 Bytes  CALL 7CA086B5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + AB                                                                          7CAE0565 112 Bytes  [ 39, 5D, 14, 74, 0B, 6A, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 44                                                                          7CAE05D6 4 Bytes  [ 75, 0C, 83, C1 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 49                                                                          7CAE05DB 90 Bytes  CALL 7CA091E5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + A4                                                                          7CAE0636 77 Bytes  CALL 7CA091E3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + F2                                                                          7CAE0684 51 Bytes  [ FF, 8B, 08, 50, FF, 51, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 126                                                                         7CAE06B8 26 Bytes  [ 08, 57, 89, 8D, EC, FD, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 4                                                                                  7CAE1106 1 Byte  [ F0 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 7                                                                                  7CAE1109 108 Bytes  [ 0C, 8B, 08, 50, FF, 51, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 74                                                                                 7CAE1176 129 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + F6                                                                                 7CAE11F8 19 Bytes  [ 38, 85, FF, 89, BD, C4, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 10A                                                                                7CAE120C 82 Bytes  [ FF, 15, 68, AF, 9F, 7C, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + 83                                                                          7CAE1E58 22 Bytes  [ FF, 50, C7, 85, A0, FB, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + 9A                                                                          7CAE1E6F 7 Bytes  [ FF, 50, 8D, 85, F4, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + A2                                                                          7CAE1E77 27 Bytes  [ 50, FF, D6, 8D, 85, A4, FB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + BE                                                                          7CAE1E93 9 Bytes  [ 15, 50, 1A, 9D, 7C, 83, BD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + C8                                                                          7CAE1E9D 23 Bytes  [ FF, 00, 74, 16, 8D, 85, F4, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 2E                                                                                7CAE2AD9 22 Bytes  [ C9, C2, 14, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 45                                                                                7CAE2AF0 14 Bytes  [ 75, 0C, 66, 83, 27, 00, BE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 54                                                                                7CAE2AFF 25 Bytes  [ FF, 85, C0, 74, 21, 33, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 6E                                                                                7CAE2B19 89 Bytes  [ 40, 08, FF, 75, 1C, 57, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + C8                                                                                7CAE2B73 75 Bytes  [ 57, FF, 75, 10, BF, 05, 40, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 36                                                                           7CAE2F06 32 Bytes  CALL 7CAE2EB2 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 57                                                                           7CAE2F27 2 Bytes  [ 55, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 5A                                                                           7CAE2F2A 7 Bytes  [ 51, 53, 56, 57, 8B, F1, 33 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 62                                                                           7CAE2F32 39 Bytes  [ F6, 46, 08, 02, 0F, 84, A1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 8B                                                                           7CAE2F5B 2 Bytes  [ 94, 17 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 4F                                                           7CAE36C6 14 Bytes  [ 33, C0, EB, 51, FF, 75, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 5E                                                           7CAE36D5 13 Bytes  CALL 7CAE326E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 6C                                                           7CAE36E3 7 Bytes  [ 75, 18, 68, 7D, 26, AE, 7C ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 74                                                           7CAE36EB 3 Bytes  [ 75, 08, E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 78                                                           7CAE36EF 13 Bytes  [ 82, 0C, 00, 8B, 4D, 1C, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 18                                                                                  7CB0DE34 8 Bytes  [ 90, 90, 90, 90, 38, 36, 9D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 21                                                                                  7CB0DE3D 22 Bytes  [ 43, 9D, 7C, 63, 7A, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 38                                                                                  7CB0DE54 1 Byte  [ FE ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 3A                                                                                  7CB0DE56 50 Bytes  [ 00, 00, 5B, CD, B0, 7C, 23, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 6F                                                                                  7CB0DE8B 5 Bytes  [ 90, 90, 8B, FF, 53 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + 4B                                                                                 7CB68ECB 26 Bytes  CALL 7CB669D2 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + 66                                                                                 7CB68EE6 118 Bytes  [ D3, 8B, 45, F8, F6, 00, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + DD                                                                                 7CB68F5D 11 Bytes  [ 75, 19, 68, 62, 63, B6, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + E9                                                                                 7CB68F69 3 Bytes  [ 6A, 0A, 6A ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + ED                                                                                 7CB68F6D 43 Bytes  [ FF, 15, 8C, 13, 9D, 7C, A3, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 1                                                                        7CB6AE6B 94 Bytes  [ D9, 74, 02, 89, 30, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 60                                                                       7CB6AECA 16 Bytes  [ 51, 0C, 8B, 45, FC, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 71                                                                       7CB6AEDB 51 Bytes  [ 51, 0C, FF, 77, 04, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + A6                                                                       7CB6AF10 12 Bytes  [ 8B, 45, EC, 8B, 08, 8D, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + B4                                                                       7CB6AF1E 47 Bytes  [ 50, FF, 11, 8B, 45, F4, 3B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIA + 1                                                                                        7CBA9353 3 Bytes  [ 15, CC, 16 ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIA + 6                                                                                        7CBA9358 11 Bytes  [ 8B, C6, 5F, 5E, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIW + 9                                                                                        7CBA9366 56 Bytes  [ 8B, FF, 55, 8B, EC, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrIA                                                                                            7CBA939F 54 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + B                                                                                          7CBA93D6 132 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + 90                                                                                         7CBA945B 10 Bytes  [ 50, 57, 68, 17, 04, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + 9B                                                                                         7CBA9466 32 Bytes  [ D3, F6, 85, ED, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + BC                                                                                         7CBA9487 21 Bytes  [ D7, 83, F8, FF, 74, 3D, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + D2                                                                                         7CBA949D 32 Bytes  [ 50, 0F, B7, 85, F4, FD, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA04                                                               774B1931 51 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA3F                                                               774B196C 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA46                                                               774B1973 3 Bytes  [ 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA4F                                                               774B197C 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA56                                                               774B1983 3 Bytes  [ 00, 00, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + B5                                                                                    774CD0F5 10 Bytes  [ 43, 6F, 6E, 76, 65, 72, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + C0                                                                                    774CD100 35 Bytes  [ 47, 65, 74, 44, 6F, 63, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + E4                                                                                    774CD124 19 Bytes  [ 6C, 6F, 62, 61, 6C, 46, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + F8                                                                                    774CD138 37 Bytes  [ 47, 65, 74, 48, 47, 6C, 6F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + 11E                                                                                   774CD15E 2 Bytes  [ 47, 65 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 52                                                                                  774CD46B 44 Bytes  [ 73, 65, 72, 55, 6E, 6D, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 7F                                                                                  774CD498 114 Bytes  [ 61, 72, 73, 68, 61, 6C, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + F2                                                                                  774CD50B 155 Bytes  [ 6C, 65, 52, 65, 67, 69, 73, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 18E                                                                                 774CD5A7 219 Bytes  [ 6F, 6E, 69, 6B, 65, 72, 52, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 26A                                                                                 774CD683 87 Bytes  [ 4F, 6C, 65, 43, 72, 65, 61, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMalloc + C5                                                                                       774CDDAD 94 Bytes  [ 55, 74, 47, 65, 74, 44, 76, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 1A                                                                                   774CDE0C 6 Bytes  [ 57, 64, 74, 70, 49, 6E ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 21                                                                                   774CDE13 71 Bytes  [ 65, 72, 66, 61, 63, 65, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 69                                                                                   774CDE5B 45 Bytes  [ 57, 72, 69, 74, 65, 43, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 97                                                                                   774CDE89 68 Bytes  [ 57, 72, 69, 74, 65, 53, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + DC                                                                                   774CDECE 17 Bytes  [ FF, 55, 8B, EC, 8B, 45, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 6A                                                                                     774CE594 64 Bytes  [ BB, 51, 4D, 77, C3, 4E, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + AB                                                                                     774CE5D5 111 Bytes  [ 90, 90, 90, 90, 8B, FF, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 11B                                                                                    774CE645 88 Bytes  [ 01, 75, 07, 51, FF, 15, 8C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 174                                                                                    774CE69E 19 Bytes  [ EC, 8B, 45, 08, 83, C0, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 18B                                                                                    774CE6B5 5 Bytes  [ 8B, FF, 55, 8B, EC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 2                                                                                         774CEDD8 9 Bytes  [ 83, C6, 48, 6A, 27, 66, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + C                                                                                         774CEDE2 4 Bytes  [ 66, 83, 66, 02 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 11                                                                                        774CEDE7 14 Bytes  [ 58, 5E, 5D, C2, 0C, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 20                                                                                        774CEDF6 3 Bytes  [ EC, 57, 33 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 24                                                                                        774CEDFA 17 Bytes  [ 39, 7D, 08, 74, 3B, E8, 62, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 52                                                                                      774CEEDC 4 Bytes  [ 84, 5B, BD, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 57                                                                                      774CEEE1 33 Bytes  [ A1, 98, 61, 5D, 77, 57, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 79                                                                                      774CEF03 4 Bytes  [ 15, 80, 12, 4B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 7E                                                                                      774CEF08 63 Bytes  [ 89, 7E, 04, 89, 06, FF, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateGuid + 37                                                                                      774CEF48 14 Bytes  [ 00, 0F, 85, 14, 85, 05, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateGuid + 47                                                                                      774CEF58 3 Bytes  [ 8B, FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 1                                                                                     774CEF5C 2 Bytes  [ EC, 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 4                                                                                     774CEF5F 30 Bytes  [ 75, 08, 56, 6A, 01, 6A, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 23                                                                                    774CEF7E 4 Bytes  [ 5E, 5D, C2, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 28                                                                                    774CEF83 18 Bytes  [ 90, 90, 90, 90, 90, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 3B                                                                                    774CEF96 73 Bytes  [ C3, 90, 6D, 52, 55, 77, D7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RegisterDragDrop + 6E                                                                                  774CF678 71 Bytes  [ 98, 85, FF, 0F, 85, E4, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RegisterDragDrop + B6                                                                                  774CF6C0 68 Bytes  [ 51, 6A, 00, FF, 35, 00, 60, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 3B                                                                                     774CF705 88 Bytes  [ CA, 83, E1, 03, F3, A4, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 94                                                                                     774CF75E 5 Bytes  [ 00, 90, 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 9A                                                                                     774CF764 51 Bytes  [ 8B, FF, 55, 8B, EC, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + CE                                                                                     774CF798 97 Bytes  [ 00, 57, 8B, 3C, 81, 85, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 130                                                                                    774CF7FA 84 Bytes  [ 08, 8B, 4D, 18, 89, 48, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + A                                                                                   774D0568 35 Bytes  [ EC, 8B, 45, 08, 8D, 50, 34, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + 2F                                                                                  774D058D 2 Bytes  [ 57, 33 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + 32                                                                                  774D0590 56 Bytes  [ F6, 46, 28, 01, 89, 7D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + B3                                                                                  774D0611 5 Bytes  [ 75, 0C, 33, DB, E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + B9                                                                                  774D0617 24 Bytes  [ DD, FF, FF, 85, C0, 0F, 84, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + 46                                                                                      774D2A6A 67 Bytes  [ 8B, 45, 14, 8B, C8, 83, E0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + 8A                                                                                      774D2AAE 28 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + A7                                                                                      774D2ACB 34 Bytes  [ 75, 0C, FF, 75, 08, E8, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + CA                                                                                      774D2AEE 7 Bytes  [ 55, 8B, EC, 51, 83, 65, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + D2                                                                                      774D2AF6 24 Bytes  [ 53, 56, 57, 6A, 2D, FF, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 8                                                                              774D2C73 85 Bytes  [ 75, 07, 4E, 48, 48, 3B, F1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 5E                                                                             774D2CC9 41 Bytes  [ 73, 46, 39, 45, FC, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 88                                                                             774D2CF3 27 Bytes  [ CA, 83, E1, 03, F3, A4, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + A4                                                                             774D2D0F 55 Bytes  [ FF, 22, 00, 22, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + DD                                                                             774D2D48 3 Bytes  [ 8B, FF, 55 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 3B                                                                           774D2E57 165 Bytes  [ 45, 10, A5, 8B, F0, 8D, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 106                                                                          774D2F22 3 Bytes  [ 55, 8B, EC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 10A                                                                          774D2F26 42 Bytes  [ C1, 8B, 4D, 08, 56, 8B, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 135                                                                          774D2F51 34 Bytes  [ 4D, 20, 89, 48, 24, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 158                                                                          774D2F74 26 Bytes  [ FF, 55, 8B, EC, 51, F6, 05, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 15                                                                                774D3B72 23 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 2D                                                                                774D3B8A 1 Byte  [ 83 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 2F                                                                                774D3B8C 23 Bytes  [ 1D, 74, 34, 2D, E6, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 47                                                                                774D3BA4 37 Bytes  [ 2D, F9, 00, 00, 00, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 6D                                                                                774D3BCA 75 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 118                                                                                 774D45D5 6 Bytes  [ 8B, CF, E8, 1D, A2, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 11F                                                                                 774D45DC 5 Bytes  [ 50, E8, 7F, A2, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 125                                                                                 774D45E2 4 Bytes  [ 85, C0, 0F, 85 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 12A                                                                                 774D45E7 133 Bytes  [ 16, 06, 00, 8D, 46, 04, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 1B0                                                                                 774D466D 37 Bytes  [ 85, FF, 7C, 30, 8B, 46, 24, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + 3A                                                                                774D4ACE 125 Bytes  [ FF, 85, C0, 7C, 07, 81, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + B8                                                                                774D4B4C 11 Bytes  [ 8B, 03, 8B, 4D, 18, 89, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + C4                                                                                774D4B58 13 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + D2                                                                                774D4B66 5 Bytes  [ 75, 1C, FF, 75, 18 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + D8                                                                                774D4B6C 2 Bytes  [ 75, 14 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateFreeThreadedMarshaler + 3B                                                                     774D5575 111 Bytes  [ 75, 0C, 33, F6, 46, 89, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateFreeThreadedMarshaler + AB                                                                     774D55E5 100 Bytes  [ 15, 5C, 10, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCallContext + 49                                                                                  774D564A 143 Bytes  [ 00, 89, 06, 33, C0, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + 58                                                                                  774D56DA 10 Bytes  [ 05, AC, 6E, 5D, 77, 8B, CE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + 63                                                                                  774D56E5 99 Bytes  [ FF, 5F, 5E, 5D, C2, 04, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + C7                                                                                  774D5749 4 Bytes  [ EC, 81, EC, 4C ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + CD                                                                                  774D574F 9 Bytes  [ 00, 53, 8B, D9, 56, 8D, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + D8                                                                                  774D575A 17 Bytes  [ 8B, 08, 57, 89, 4D, F4, 03, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + 10                                                                             774D6A2F 183 Bytes  [ 89, 45, AC, 8B, 06, 33, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + C8                                                                             774D6AE7 31 Bytes  [ 5D, C4, 7C, 40, FF, 75, AC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + E8                                                                             774D6B07 5 Bytes  [ 45, C0, 8B, 08, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + EE                                                                             774D6B0D 36 Bytes  [ 51, 08, 39, 7D, C4, 8B, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + 116                                                                            774D6B35 5 Bytes  [ 8B, FF, 55, 8B, EC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 2F                                                                              774D6D1C 100 Bytes  [ 00, 00, 8B, 5E, 38, 89, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 94                                                                              774D6D81 8 Bytes  [ 85, C0, 89, 45, E8, 0F, 8C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 9D                                                                              774D6D8A 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + A8                                                                              774D6D95 57 Bytes  CALL EECA2E1F 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + E3                                                                              774D6DD0 155 Bytes  [ 89, 45, E0, B9, A0, 61, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 7D                                                                             774D806D 15 Bytes  [ 0F, 85, D4, 02, 00, 00, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 8D                                                                             774D807D 26 Bytes  [ 8D, BD, B4, FB, FF, FF, AB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + A9                                                                             774D8099 47 Bytes  [ 89, 9D, D0, FB, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + DA                                                                             774D80CA 55 Bytes  [ 0F, 85, BF, D1, 00, 00, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 112                                                                            774D8102 35 Bytes  [ 93, 5D, 77, FF, 15, 04, 16, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 2                                                                               774DA340 34 Bytes  [ FF, 0F, 8C, 84, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 25                                                                              774DA363 5 Bytes  [ B5, E0, FD, FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 2B                                                                              774DA369 20 Bytes  [ D6, 85, C0, 0F, 85, 81, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 40                                                                              774DA37E 69 Bytes  [ FF, 50, 8D, 85, D4, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 86                                                                              774DA3C4 41 Bytes  [ 15, 40, 10, 4B, 77, 5F, 5E, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetProxyBlanket + 12                                                                                 774DAD35 3 Bytes  [ EC, FF, 75 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 45                                                                                     774DAD99 31 Bytes  [ C8, 8D, 45, D4, 6A, 01, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 67                                                                                     774DADBB 43 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 93                                                                                     774DADE7 62 Bytes  [ 00, FF, 75, 10, 8B, 40, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 3A                                                                                      774DAE26 199 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 102                                                                                     774DAEEE 1 Byte  [ 4D ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 104                                                                                     774DAEF0 7 Bytes  [ 56, FF, 75, 0C, E8, 2D, A3 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 10D                                                                                     774DAEF9 34 Bytes  [ 85, C0, 0F, 85, A9, 1D, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 130                                                                                     774DAF1C 11 Bytes  [ 00, A1, 04, 60, 5D, 77, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 17                                                                                       774DF9CE 1 Byte  [ E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 1A                                                                                       774DF9D1 2 Bytes  [ 70, D0 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 21                                                                                       774DF9D8 29 Bytes  [ 3B, C3, 0F, 8C, E5, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 40                                                                                       774DF9F7 254 Bytes  [ 06, 8D, 4D, EC, 51, 68, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 13F                                                                                      774DFAF6 4 Bytes  [ 3D, 02, 40, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSwitchCallContext + 24                                                                               774DFC1B 20 Bytes  [ 85, 64, FF, FF, FF, 8B, 78, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 1                                                                                     774DFC30 4 Bytes  [ 06, 8D, 4D, 80 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 7                                                                                     774DFC36 58 Bytes  [ 8D, 6C, FF, FF, FF, 51, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 42                                                                                    774DFC71 2 Bytes  [ 45, 80 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 45                                                                                    774DFC74 15 Bytes  [ 75, 8C, 8D, 8D, 74, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 55                                                                                    774DFC84 43 Bytes  [ FF, F7, DF, 1B, FF, 6A, 04, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + A                                                                               774E06A0 75 Bytes  [ 85, DB, 0F, 85, 43, 77, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 56                                                                              774E06EC 57 Bytes  [ FF, 75, 10, 8B, 45, 08, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 90                                                                              774E0726 4 Bytes  [ F9, 89, 45, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 95                                                                              774E072B 54 Bytes  [ 47, 04, F7, D0, A8, 01, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + CC                                                                              774E0762 6 Bytes  [ F8, 85, FF, 0F, 8C, F9 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 11                                                                      774E14B5 241 Bytes  [ 08, 50, FF, 51, 08, 89, 3D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 103                                                                     774E15A7 24 Bytes  [ 75, 10, 8B, 5D, 0C, E9, 0B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 11C                                                                     774E15C0 4 Bytes  [ 8F, 24, CF, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 160                                                                     774E1604 29 Bytes  [ 8B, 3D, A4, 10, 4B, 77, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 17E                                                                     774E1622 3 Bytes  [ 1D, 24, 12 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + 24                                                                                   774E3BC0 92 Bytes  [ 85, C0, 74, 1E, 89, 73, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + 81                                                                                   774E3C1D 64 Bytes  [ 90, 90, 90, FF, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + C2                                                                                   774E3C5E 23 Bytes  [ 5E, C9, C2, 08, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 13                                                                                774E3C76 19 Bytes  [ 0F, 85, B3, 2A, 04, 00, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 27                                                                                774E3C8A 46 Bytes  [ 75, 0C, 8B, CF, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 56                                                                                774E3CB9 8 Bytes  [ 80, 05, 00, 5F, 5E, 5D, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 5F                                                                                774E3CC2 6 Bytes  [ 90, 90, 90, 90, 90, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 66                                                                                774E3CC9 17 Bytes  [ 55, 8B, EC, 8D, 45, 0C, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 31                                                                                774E4032 59 Bytes  [ 51, 04, 83, C6, 54, 56, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 6D                                                                                774E406E 35 Bytes  [ 55, 8B, EC, 56, 8B, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 91                                                                                774E4092 53 Bytes  [ 55, 8B, EC, 8B, 45, 0C, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + C7                                                                                774E40C8 210 Bytes  [ F0, 33, DB, F3, A7, 0F, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 19A                                                                               774E419B 9 Bytes  [ 4C, 77, C7, 46, 18, 74, 22, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 22                                                                                       774E4752 76 Bytes  [ 07, 50, FF, 15, 28, 15, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 6F                                                                                       774E479F 32 Bytes  [ FF, 89, 73, 74, 0F, B6, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 90                                                                                       774E47C0 37 Bytes  [ FF, 89, 46, 28, 8D, 46, 38, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + B6                                                                                       774E47E6 7 Bytes  [ FF, 50, 8D, 4D, FC, E8, 0A ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + BE                                                                                       774E47EE 5 Bytes  [ 00, 00, E9, 46, D8 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 10                                                                             774E6E47 76 Bytes  [ 01, 00, 8B, 4E, 40, 56, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 5D                                                                             774E6E94 64 Bytes  [ 6A, 04, 8D, 45, CC, 50, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 9E                                                                             774E6ED5 145 Bytes  [ 85, B1, E1, 04, 00, 57, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 130                                                                            774E6F67 31 Bytes  [ 76, 38, 8D, 46, 28, FF, 76, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 150                                                                            774E6F87 36 Bytes  [ 08, FF, FF, 00, 80, E9, C7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 6F                                                                               774E7633 3 Bytes  [ 11, A2, 05 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 73                                                                               774E7637 39 Bytes  [ 8B, 45, 0C, 89, 08, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 9B                                                                               774E765F 113 Bytes  [ 8B, 75, 0C, 57, 6A, 04, 59, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 10D                                                                              774E76D1 39 Bytes  [ B8, 02, 40, 00, 80, 5F, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 135                                                                              774E76F9 63 Bytes  [ 00, F7, D8, 1B, C0, F7, D8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 25                                                                                  774E849F 146 Bytes  [ 00, 00, 85, C0, 0F, 8C, 29, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + B8                                                                                  774E8532 33 Bytes  CALL 004E8538 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 136                                                                                 774E85B0 9 Bytes  [ B9, 68, 60, 5D, 77, E8, F5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 14F                                                                                 774E85C9 12 Bytes  [ 56, 8B, 75, 08, 85, F6, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 15C                                                                                 774E85D6 10 Bytes  [ 06, 8D, 4D, 08, 51, 68, 3C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetErrorInfo + 5D                                                                                      774E947C 68 Bytes  [ 55, 8B, EC, 51, 53, 57, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetErrorInfo + A2                                                                                      774E94C1 317 Bytes  [ 83, F8, 15, 0F, 8F, A3, 5C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + 9D                                                                               774E95FF 11 Bytes  [ 56, 04, 00, 8D, 85, F8, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + A9                                                                               774E960B 2 Bytes  [ 73, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + AE                                                                               774E9610 26 Bytes  [ F8, 85, FF, 0F, 8C, 08, 94, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + C9                                                                               774E962B 23 Bytes  [ FF, 50, 68, CC, EE, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + E1                                                                               774E9643 42 Bytes  [ B5, F8, FD, FF, FF, FF, 15, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 6                                                                                    774EA5B5 5 Bytes  [ 56, 57, 33, FF, BE ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + C                                                                                    774EA5BB 45 Bytes  [ 60, 5D, 77, 8B, CE, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + D8                                                                                   774EA687 58 Bytes  [ 01, 04, 80, EB, F4, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 113                                                                                  774EA6C2 55 Bytes  [ 45, E4, 50, FF, 35, D8, 6D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 14B                                                                                  774EA6FA 17 Bytes  [ C9, C2, 08, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 4                                                                                  774EE4B0 65 Bytes  [ C7, 5F, 5E, 5D, C2, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 46                                                                                 774EE4F2 2 Bytes  [ 55, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 49                                                                                 774EE4F5 48 Bytes  [ 53, 8B, 5D, 0C, 85, DB, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 7A                                                                                 774EE526 130 Bytes  [ C0, 7C, 0A, 8B, 45, 0C, 0D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + FD                                                                                 774EE5A9 12 Bytes  [ 8B, 45, 0C, 8B, 08, 56, 68, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 14                                                                                774EFA56 36 Bytes  [ 57, FF, 75, 18, FF, 75, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 39                                                                                774EFA7B 75 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 85                                                                                774EFAC7 17 Bytes  CALL CA4EFAC9 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 97                                                                                774EFAD9 10 Bytes  [ F0, 85, F6, 0F, 8C, A1, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + A3                                                                                774EFAE5 212 Bytes  [ 08, 57, BF, 6C, CA, 4B, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 2F                                                                                   774EFD69 107 Bytes  [ 00, 75, 30, FF, 75, 08, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 9B                                                                                   774EFDD5 28 Bytes  [ 75, FC, FF, 15, 40, 10, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + B8                                                                                   774EFDF2 12 Bytes  [ 83, FB, 01, 0F, 82, 9F, D4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + C5                                                                                   774EFDFF 82 Bytes  [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 118                                                                                  774EFE52 14 Bytes  [ C3, 5B, 5D, C2, 0C, 00, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 54                                                                                774F09F3 13 Bytes  [ 74, 1D, 56, 33, F6, 39, 35, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 62                                                                                774F0A01 17 Bytes  [ 4C, F0, 04, 85, C9, 75, 25, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 74                                                                                774F0A13 26 Bytes  [ 6A, 00, FF, 35, 00, 60, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + D0                                                                                774F0A6F 3 Bytes  [ 33, E1, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + D4                                                                                774F0A73 204 Bytes  [ 85, C0, 0F, 84, 63, D5, 03, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + AB                                                                             774F391F 23 Bytes  [ 4D, 0C, 89, 08, 57, 8B, CE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + C3                                                                             774F3937 46 Bytes  CALL 775117D3 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + F2                                                                             774F3966 9 Bytes  [ 3B, 46, 48, 0F, 82, 0C, DF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + FC                                                                             774F3970 54 Bytes  [ 7E, 40, FF, 74, 1D, 6A, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + 134                                                                            774F39A8 3 Bytes  [ 90, 90, 90 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 2                                                                                  774F3EE9 114 Bytes  [ 15, 2C, 14, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 75                                                                                 774F3F5C 27 Bytes  [ 45, FC, 5B, 5E, C9, C2, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 91                                                                                 774F3F78 299 Bytes  [ 02, 75, 0A, F6, 41, 08, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 1BD                                                                                774F40A4 19 Bytes  [ 88, 5D, ED, 88, 5D, EE, 88, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 202                                                                                774F40E9 8 Bytes  CALL CAA2943E 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 37                                                                                   774F46AF 75 Bytes  [ 60, 5D, 77, FF, 15, 54, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 85                                                                                   774F46FD 114 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + F8                                                                                   774F4770 72 Bytes  [ 5F, 5E, 5D, C2, 04, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 144                                                                                  774F47BC 45 Bytes  [ 8B, FF, 55, 8B, EC, F6, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 172                                                                                  774F47EA 13 Bytes  [ 45, 08, 83, 08, FF, EB, E1, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + A3                                                                              774F5BA6 26 Bytes  [ 00, 10, 0F, 85, AC, 0E, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + BE                                                                              774F5BC1 4 Bytes  [ 84, 28, 23, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + F5                                                                              774F5BF8 12 Bytes  [ 75, 1D, A8, 08, 74, 19, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + 102                                                                             774F5C05 55 Bytes  [ 66, 64, 00, 83, 66, 60, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + 13A                                                                             774F5C3D 37 Bytes  [ 83, 7D, FC, 00, 74, 0A, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + B8                                                                             774F681F 96 Bytes  [ 4E, 64, 8B, 49, 20, 3B, C8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 119                                                                            774F6880 26 Bytes  [ FF, 51, 0C, 85, C0, 7C, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 134                                                                            774F689B 1 Byte  [ F6 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 136                                                                            774F689D 1 Byte  [ 8C ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 13B                                                                            774F68A2 58 Bytes  [ 83, 7F, 04, 08, 0F, 85, 99, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax                                                                                    774F7DC7 33 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 22                                                                               774F7DE9 3 Bytes  [ BF, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 29                                                                               774F7DF0 7 Bytes  [ 59, 53, 8D, 86, B4, 01, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 31                                                                               774F7DF8 82 Bytes  [ 50, BB, 57, 00, 07, 80, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 85                                                                               774F7E4C 1 Byte  [ 5D ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface                                                                                   774F7EFB 6 Bytes  [ 90, 90, 8B, FF, 55, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + 7                                                                               774F7F02 183 Bytes  [ 83, EC, 34, 53, 8B, D9, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + BF                                                                              774F7FBA 32 Bytes  [ 45, FC, 2B, F0, 39, 55, E0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + E0                                                                              774F7FDB 18 Bytes  [ 15, 54, 61, 5D, 77, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + F4                                                                              774F7FEF 1 Byte  [ D4 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 24                                                                               774F9AFB 229 Bytes  [ 7C, 61, F6, 45, 0D, 40, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 10C                                                                              774F9BE3 41 Bytes  [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 136                                                                              774F9C0D 77 Bytes  [ 47, 04, 5F, 5E, 5D, C2, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 184                                                                              774F9C5B 8 Bytes  [ 45, FC, 89, 43, 04, 8B, 48, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 18D                                                                              774F9C64 15 Bytes  [ 0B, FF, 40, 10, 89, 58, 14, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 45                                                                                 774FA061 10 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 50                                                                                 774FA06C 27 Bytes  [ 4D, 08, 6A, 01, FF, 75, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 6C                                                                                 774FA088 39 Bytes  [ FF, 55, 8B, EC, 83, EC, 2C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 94                                                                                 774FA0B0 44 Bytes  [ FF, FF, 3B, C6, 89, 45, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + C1                                                                                 774FA0DD 3 Bytes  [ 25, F0, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 5A                                                                                      774FA14B 2 Bytes  [ 0F, B7 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 5D                                                                                      774FA14E 23 Bytes  [ 0C, 83, 24, 87, 00, FF, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 75                                                                                      774FA166 68 Bytes  [ FF, FF, B9, F8, 6D, 5D, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + BB                                                                                      774FA1AC 16 Bytes  [ B5, CF, FF, FF, 8B, 08, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 11C                                                                                     774FA20D 1 Byte  [ 25 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 13                                                                            774FA2E3 39 Bytes  [ 00, 00, 3B, C7, 0F, 84, 16, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 3B                                                                            774FA30B 38 Bytes  [ 90, 90, 90, 90, 90, 8B, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 62                                                                            774FA332 66 Bytes  [ 01, 80, 0F, 84, F4, DE, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + A6                                                                            774FA376 100 Bytes  [ 8D, B0, 80, 00, 00, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 10B                                                                           774FA3DB 187 Bytes  [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 80                                                                             774FB51E 77 Bytes  [ 00, 8B, 7D, 14, 3B, FB, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + CE                                                                             774FB56C 28 Bytes  [ C0, 0F, 85, 42, 45, 03, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + EB                                                                             774FB589 54 Bytes  [ 85, C0, 0F, 85, 5D, 45, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 122                                                                            774FB5C0 80 Bytes  [ FF, FF, 75, 10, 8B, B5, 3C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 173                                                                            774FB611 156 Bytes  [ 5D, 18, F6, C7, 20, 56, 57, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 25                                                                                    774FC9F0 20 Bytes  [ 00, 8D, 45, C4, 50, 6A, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 3A                                                                                    774FCA05 203 Bytes  [ 15, 58, 10, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 106                                                                                   774FCAD1 29 Bytes  [ FF, 3B, C6, 89, 45, F8, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 124                                                                                   774FCAEF 70 Bytes  [ FF, 15, E4, 12, 4B, 77, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 16B                                                                                   774FCB36 1 Byte  [ 4F ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 1F                                                                                  775029CD 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 23                                                                                  775029D1 5 Bytes  [ FF, 55, 8B, EC, 51 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 29                                                                                  775029D7 88 Bytes  [ 56, 57, 8B, 3D, 8C, 14, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 31                                                                                    77502A30 4 Bytes  [ 85, 23, 8B, 03 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 36                                                                                    77502A35 13 Bytes  [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 44                                                                                    77502A43 5 Bytes  [ 50, 04, 85, C0, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 4A                                                                                    77502A49 149 Bytes  [ C4, 54, FE, FF, C7, 46, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + E0                                                                                    77502ADF 2 Bytes  [ 47, 10 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 2D                                                                                     77502C71 38 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 54                                                                                     77502C98 2 Bytes  [ 46, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 57                                                                                     77502C9B 31 Bytes  [ 0E, 89, 08, 89, 41, 04, 5F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 77                                                                                     77502CBB 41 Bytes  [ FF, 55, 8B, EC, 83, EC, 1C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + A1                                                                                     77502CE5 4 Bytes  CALL 775033AA C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserFree + E                                                                                77502EA6 13 Bytes  [ FF, 5E, C9, C3, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserFree + 1F                                                                               77502EB7 145 Bytes  [ 8B, C0, C3, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 3F                                                                                   77502F4A 66 Bytes  [ 0D, D4, 62, 5D, 77, 85, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 82                                                                                   77502F8D 8 Bytes  [ FC, FF, 8B, C6, 5E, 5D, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 8B                                                                                   77502F96 70 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + D2                                                                                   77502FDD 89 Bytes  [ 3D, 30, 12, 4B, 77, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 12C                                                                                  77503037 102 Bytes  [ 33, C0, 5F, 5E, 5B, C9, C3, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize                                                                                        77503343 50 Bytes  [ 90, 8B, FF, 55, 8B, EC, A1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + 33                                                                                   77503376 103 Bytes  [ 8D, 4D, E4, C7, 45, E4, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + 9E                                                                                   775033E1 22 Bytes  [ 90, 8B, FF, 55, 8B, EC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + B5                                                                                   775033F8 16 Bytes  [ 8B, 49, 08, 83, C2, 10, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + C6                                                                                   77503409 18 Bytes  [ 5D, C2, 04, 00, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryLinkFromData + 11                                                                              77503503 3 Bytes  [ 2C, 30, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryLinkFromData + 15                                                                              77503507 44 Bytes  [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 10                                                                            77503534 40 Bytes  [ 00, 00, 8B, 00, 03, 46, 40, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 39                                                                            7750355D 8 Bytes  [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 42                                                                            77503566 110 Bytes  [ 00, 03, 46, 40, 89, 08, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + B1                                                                            775035D5 56 Bytes  [ 75, 18, FF, 75, 14, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + EA                                                                            7750360E 33 Bytes  [ F9, 8B, 57, 74, 33, C0, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 12                                                                              77503D05 58 Bytes  [ 39, 41, 6C, 74, 11, 64, A1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 4D                                                                              77503D40 9 Bytes  [ F8, 0F, 8D, 4B, FC, FE, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 57                                                                              77503D4A 5 Bytes  [ FE, FF, 33, C0, E9 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 5D                                                                              77503D50 33 Bytes  [ 2C, 01, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 7F                                                                              77503D72 52 Bytes  [ 8B, 45, 08, 57, 0F, 84, 91, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B                                                                                  77503FB3 26 Bytes  [ 00, 00, 8B, 80, B0, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + 26                                                                                 77503FCE 137 Bytes  [ 01, 5F, C9, C2, 04, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B0                                                                                 77504058 3 Bytes  [ 85, 23, 06 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B5                                                                                 7750405D 38 Bytes  [ 5D, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + DC                                                                                 77504084 12 Bytes  [ D6, 85, C0, 75, 4E, 0F, B7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 1B                                                                               7750467A 13 Bytes  [ 8B, EC, 83, 39, 00, 56, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 2A                                                                               77504689 76 Bytes  [ 80, 80, 0F, 00, 00, 8B, 30, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 78                                                                               775046D7 7 Bytes  [ FF, 3D, 57, 44, 46, 4C, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 80                                                                               775046DF 40 Bytes  [ 79, E5, 03, 00, 5D, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + A9                                                                               77504708 13 Bytes  [ 00, 8B, 80, 80, 0F, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 2D                                                                              77504811 13 Bytes  CALL 77503C1B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 3B                                                                              7750481F 47 Bytes  [ C1, EE, 10, 56, 8B, CF, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 6B                                                                              7750484F 256 Bytes  [ 00, 89, 45, FC, 5F, 5E, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 16C                                                                             77504950 55 Bytes  [ FF, 0F, 8D, 28, 14, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 1A5                                                                             77504989 9 Bytes  [ BE, 57, 00, 07, 80, E9, C5, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 2                                                                                        77505491 16 Bytes  [ FF, BB, 57, 00, 07, 80, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 44                                                                                       775054D3 6 Bytes  [ FF, 50, E8, 4C, FD, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 4B                                                                                       775054DA 109 Bytes  [ 85, C0, 0F, 85, 95, B1, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + E4                                                                                       77505573 8 Bytes  CALL 775296C1 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + ED                                                                                       7750557C 68 Bytes  [ F0, 85, F6, 0F, 85, 3C, 22, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 1D                                                                                  7750AF8C 147 Bytes  [ 05, 00, 8D, 50, 02, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + B1                                                                                  7750B020 153 Bytes  [ 5D, FC, 0F, B6, 06, 33, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 14B                                                                                 7750B0BA 77 Bytes  [ 24, F8, E5, 4B, 77, 53, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 199                                                                                 7750B108 94 Bytes  [ 3B, DF, 0F, 84, 82, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 1F8                                                                                 7750B167 124 Bytes  [ EC, 83, EC, 0C, 8B, 4D, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + C7                                                                            7750E198 32 Bytes  [ 8D, 46, 24, 50, FF, 15, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + E8                                                                            7750E1B9 37 Bytes  [ FF, FF, FF, 34, E0, 53, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 10E                                                                           7750E1DF 27 Bytes  [ 00, 00, 89, 41, 0C, 89, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 12B                                                                           7750E1FC 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 12F                                                                           7750E200 86 Bytes  [ FF, 55, 8B, EC, 56, 8B, F1, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + F                                                                                    7750F4F5 9 Bytes  [ EC, 51, 51, 83, 65, F8, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 19                                                                                   7750F4FF 26 Bytes  [ 00, 66, F7, 45, 0E, 07, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 34                                                                                   7750F51A 53 Bytes  [ 00, 56, 68, D8, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 6A                                                                                   7750F550 23 Bytes  [ 00, 00, 8B, F8, 85, FF, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + F                                                                                      7750F568 11 Bytes  [ 7C, 0C, 8B, 45, FC, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 1B                                                                                     7750F574 20 Bytes  [ 89, 01, 5E, 8D, 45, F8, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 30                                                                                     7750F589 74 Bytes  [ 81, FF, 20, 00, 03, 80, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 7B                                                                                     7750F5D4 96 Bytes  [ 03, 00, F6, 45, 10, 02, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + DC                                                                                     7750F635 18 Bytes  [ FF, FF, 8B, F0, 3B, F3, 7C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 17                                                                                  77514CD2 3 Bytes  [ C8, D2, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 1B                                                                                  77514CD6 37 Bytes  [ 8B, F8, 85, FF, 0F, 8C, 1E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 41                                                                                  77514CFC 15 Bytes  [ 74, 40, 83, 7D, E4, FF, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 74                                                                                  77514D2F 4 Bytes  [ 33, C0, 8A, 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 79                                                                                  77514D34 57 Bytes  [ F7, D0, A8, 01, 0F, 85, 34, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStg + 2                                                                                      77515F45 24 Bytes  [ B5, FF, FF, 39, 5E, 14, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStg + 1B                                                                                     77515F5E 33 Bytes  [ 00, 03, 46, 14, 3B, C3, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 13                                                                                      77515F80 10 Bytes  [ 00, 03, 46, 18, 3B, C3, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 1E                                                                                      77515F8B 69 Bytes  [ FF, 33, D2, 39, 5E, 08, 76, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 64                                                                                      77515FD1 5 Bytes  [ 8B, 00, 03, 46, 18 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 6A                                                                                      77515FD7 33 Bytes  [ 04, 90, 42, 89, 01, 3B, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 8C                                                                                      77515FF9 71 Bytes  [ 8B, 08, 03, 4E, 10, E8, 91, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 1                                                                                 77517183 94 Bytes  [ 75, 0C, 57, 83, EC, 10, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 60                                                                                775171E2 94 Bytes  [ 8B, FC, 8D, 75, EC, A5, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + BF                                                                                77517241 48 Bytes  [ EC, 81, EC, 20, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + F0                                                                                77517272 18 Bytes  [ 85, C0, 0F, 84, 1D, 42, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 103                                                                               77517285 57 Bytes  CALL 775172C0 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 2                                                                                77517680 46 Bytes  [ 7F, 0F, 83, EC, 73, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 31                                                                               775176AF 65 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 73                                                                               775176F1 60 Bytes  [ 15, AC, 14, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + B0                                                                               7751772E 88 Bytes  [ FF, 55, 8B, EC, 51, 53, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 109                                                                              77517787 78 Bytes  [ F8, 85, FF, 0F, 84, 1E, 72, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 4                                                                                  77517922 46 Bytes  [ 75, 08, 6A, 00, 57, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 33                                                                                 77517951 103 Bytes  [ FF, 53, 56, 8B, F1, 57, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 9B                                                                                 775179B9 4 Bytes  [ C6, 5E, 5B, C3 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + A0                                                                                 775179BE 24 Bytes  [ 7D, 0C, 00, 0F, 85, 73, 3C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + B9                                                                                 775179D7 183 Bytes  CALL 775179E8 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 34                                                                                      775196D6 152 Bytes  [ 55, 8B, EC, 83, EC, 0C, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 136                                                                                     775197D8 24 Bytes  JMP 7751989A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 14F                                                                                     775197F1 93 Bytes  [ 56, 20, 8B, 4D, 10, 8B, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 1AD                                                                                     7751984F 64 Bytes  [ 8B, F8, 85, FF, 0F, 8C, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 1EE                                                                                     77519890 21 Bytes  [ 10, 8B, CE, FF, 75, 0C, 53, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 29                                                                             7751A015 6 Bytes  [ 8B, 76, 20, 8B, 06, 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 30                                                                             7751A01C 89 Bytes  [ 50, 04, 8B, C6, 5E, C3, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 8A                                                                             7751A076 82 Bytes  [ 07, 80, EB, F3, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + FC                                                                             7751A0E8 53 Bytes  [ 3F, 8D, 4C, 09, 02, 8B, C1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 132                                                                            7751A11E 30 Bytes  [ C8, 83, E1, 03, F3, A4, 33, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus                                                                                    7751A3F9 41 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 2A                                                                               7751A423 84 Bytes  [ 00, 00, 89, 06, F7, D8, 1B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 7F                                                                               7751A478 125 Bytes  [ 50, 04, 8B, C6, 5E, 5D, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + FD                                                                               7751A4F6 49 Bytes  [ 33, C0, 5F, 5E, 5D, C2, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 12F                                                                              7751A528 34 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 36                                                                          7751A78D 11 Bytes  [ CE, 0F, 85, 7A, 53, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 42                                                                          7751A799 6 Bytes  [ 8B, F8, 3B, FB, 0F, 8C ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 49                                                                          7751A7A0 16 Bytes  [ 53, 01, 00, 83, 4E, 44, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 5A                                                                          7751A7B1 111 Bytes  [ 8B, C7, 5F, 5E, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + CA                                                                          7751A821 51 Bytes  [ 50, FF, 51, 60, 5D, C2, 0C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 2                                                                                  7751B1FA 19 Bytes  [ 51, 08, 5F, 8B, C6, 5B, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 16                                                                                 7751B20E 1 Byte  [ FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 18                                                                                 7751B210 58 Bytes  [ EB, BE, FF, FF, 00, 80, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 53                                                                                 7751B24B 17 Bytes  CALL 7751B21C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 65                                                                                 7751B25D 60 Bytes  [ 8D, 4F, 5C, 89, 4D, 0C, E9, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 12                                                                            7751B627 70 Bytes  [ 15, D4, 18, 4B, 77, 83, C4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 59                                                                            7751B66E 47 Bytes  [ 75, 08, 8D, 75, FC, E8, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 89                                                                            7751B69E 36 Bytes  [ 04, 85, C0, 0F, 84, 78, 9E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 52                                                                             7751B6FE 22 Bytes  [ 80, 3F, 03, 0F, 84, A6, 1B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 69                                                                             7751B715 14 Bytes  [ EC, 8B, 45, 10, 85, C0, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 78                                                                             7751B724 138 Bytes  [ 8B, 75, 0C, 83, C6, 03, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 103                                                                            7751B7AF 32 Bytes  [ 37, FF, 15, 18, 11, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 124                                                                            7751B7D0 1 Byte  [ 55 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 2                                                                              7751B95F 15 Bytes  [ 39, 7E, 70, 0F, 85, DF, 19, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 12                                                                             7751B96F 37 Bytes  [ FF, 8B, C3, 5F, 5E, 5B, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 38                                                                             7751B995 7 Bytes  [ 85, C0, 0F, 84, D5, 57, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 3B                                                                           7751B9E3 50 Bytes  [ EC, 51, 51, 83, 65, FC, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 6E                                                                           7751BA16 37 Bytes  [ 8B, 75, 0C, 85, F6, 74, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 94                                                                           7751BA3C 113 Bytes  [ 85, F6, 89, 73, 48, 74, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 106                                                                          7751BAAE 132 Bytes  [ 55, 8B, EC, 51, 53, 8B, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 18B                                                                          7751BB33 31 Bytes  [ 08, 50, FF, 51, 20, 8B, F8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 2                                                                               7751C85E 45 Bytes  [ 75, 0C, FF, 75, 08, E8, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 30                                                                              7751C88C 27 Bytes  [ 00, 53, 56, 8B, 75, 0C, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 4C                                                                              7751C8A8 21 Bytes  [ 51, 68, 00, 08, 00, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 62                                                                              7751C8BE 55 Bytes  [ FF, 7C, 13, FF, 75, 10, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 9A                                                                              7751C8F6 42 Bytes  [ FF, 55, 8B, EC, 8B, 45, 14, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 26                                                                             7751CA30 33 Bytes  [ 23, 00, 00, 8B, F8, 85, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 48                                                                             7751CA52 75 Bytes  [ 21, 7D, E0, 8D, 45, CC, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 94                                                                             7751CA9E 54 Bytes  [ 45, E4, 56, FF, 75, D0, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + CB                                                                             7751CAD5 9 Bytes  [ 83, 7D, E0, 00, 0F, 85, 16, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + D5                                                                             7751CADF 95 Bytes  [ 83, 7D, CC, 00, 0F, 85, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + C7                                                                                7751DE16 62 Bytes  [ C0, 8B, 35, 40, 10, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 10F                                                                               7751DE5E 14 Bytes  [ 83, EC, 20, 66, A1, 60, 62, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 11E                                                                               7751DE6D 16 Bytes  [ F6, 89, 75, E4, C7, 45, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 12F                                                                               7751DE7E 53 Bytes  [ F0, 04, 00, 00, 00, E8, 16, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 165                                                                               7751DEB4 87 Bytes  [ 45, F8, 57, 8B, 38, 56, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + A8                                                                                           7751F3B6 52 Bytes  [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + DD                                                                                           7751F3EB 6 Bytes  CALL 77503774 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + E4                                                                                           7751F3F2 22 Bytes  [ F8, 3B, FB, 0F, 8C, F0, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + FC                                                                                           7751F40A 4 Bytes  [ 8B, 80, 80, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + 101                                                                                          7751F40F 59 Bytes  [ 00, 8B, 00, 03, 46, 70, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 10                                                                          775209CF 13 Bytes  [ 8B, 08, 50, FF, 51, 08, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 1E                                                                          775209DD 12 Bytes  [ B5, E4, FE, FF, FF, 8D, 46, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 2B                                                                          775209EA 12 Bytes  [ 1B, C0, 57, 23, C1, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 38                                                                          775209F7 3 Bytes  [ 71, FC, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 3C                                                                          775209FB 59 Bytes  [ 8B, F8, 33, C0, 3B, F8, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + A                                                                          77520DDD 55 Bytes  [ 00, 39, 7D, 08, 89, 7E, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 42                                                                         77520E15 1 Byte  [ 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 44                                                                         77520E17 66 Bytes  [ EC, 56, 8B, 75, 08, 8D, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 87                                                                         77520E5A 2 Bytes  [ CF, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 8B                                                                         77520E5E 31 Bytes  [ C3, 90, 90, 90, 90, 90, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + 82                                                                      77520F85 48 Bytes  [ 33, F6, 8B, 4D, 08, E8, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + B3                                                                      77520FB6 8 Bytes  [ 55, 8B, EC, 56, 8B, F1, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + BD                                                                      77520FC0 26 Bytes  [ 00, F6, 45, 08, 01, 74, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + D8                                                                      77520FDB 10 Bytes  [ 04, 00, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + E3                                                                      77520FE6 72 Bytes  [ F1, 8B, 46, 14, 57, 33, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + E                                                                                    7752207F 25 Bytes  [ 5F, 8B, C6, 5E, C9, C2, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 28                                                                                   77522099 23 Bytes  [ F7, EF, FC, FF, 8B, C8, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 40                                                                                   775220B1 39 Bytes  [ 15, 50, 61, 5D, 77, E9, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 68                                                                                   775220D9 66 Bytes  [ FF, 36, 50, FF, 75, 08, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + AB                                                                                   7752211C 69 Bytes  [ 46, 3D, FF, 7F, 00, 00, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 2C                                                                               77522ABA 18 Bytes  [ 00, FF, B5, 58, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 60                                                                               77522AEE 1 Byte  [ 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 62                                                                               77522AF0 10 Bytes  [ 35, 50, 10, 4B, 77, 57, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 6D                                                                               77522AFB 17 Bytes  [ 75, 08, 33, FF, 68, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserMarshal + A                                                                             77522B0E 72 Bytes  [ BF, F3, 01, 04, 80, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserMarshal + 53                                                                            77522B57 40 Bytes  [ 84, 80, 20, FC, FF, E9, F4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + B                                                                              77522B80 6 Bytes  [ 85, C0, 59, 74, 39, 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 12                                                                             77522B87 47 Bytes  CALL 77522BC6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 54                                                                             77522BC9 30 Bytes  [ 55, 8B, EC, 53, 56, 57, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 73                                                                             77522BE8 85 Bytes  [ BE, 3C, 1A, 4B, 77, A5, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserSize + 50                                                                                77522C3E 101 Bytes  [ 00, 00, EB, 56, C7, 46, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserFree + 48                                                                                77522CA4 50 Bytes  [ 15, 24, 12, 4B, 77, 83, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserFree + 7B                                                                                77522CD7 149 Bytes  [ 80, 80, 0F, 00, 00, 8B, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserUnmarshal + 71                                                                           77522D6D 133 Bytes  CALL 77522D7B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserUnmarshal + F7                                                                           77522DF3 59 Bytes  [ 5E, C3, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + 2                                                                           77522E2F 106 Bytes  [ 15, 54, 61, 5D, 77, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + 6D                                                                          77522E9A 84 Bytes  [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + C2                                                                          77522EEF 15 Bytes  [ 83, 4D, FC, FF, 8B, 45, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + D2                                                                          77522EFF 1 Byte  [ 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + D4                                                                          77522F01 12 Bytes  [ FF, FF, FF, CC, 1B, 53, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 7                                                                                77523191 11 Bytes  [ D8, 85, DB, 0F, 8C, 41, CE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 13                                                                               7752319D 59 Bytes  [ 0A, 8B, 4D, F8, 8B, 3C, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 4F                                                                               775231D9 30 Bytes  [ 02, 0F, B7, 49, 1C, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 6E                                                                               775231F8 1 Byte  [ 98 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 70                                                                               775231FA 114 Bytes  CALL 77523209 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + 4A                                                                                  7752326D 93 Bytes  [ 7D, A0, C7, 04, 87, FC, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + A8                                                                                  775232CB 34 Bytes  [ FF, 55, 8B, EC, 51, 51, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + CC                                                                                  775232EF 34 Bytes  [ 03, 46, 18, 39, 58, 1C, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + EF                                                                                  77523312 10 Bytes  [ 03, 46, 18, 39, 5E, 18, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + FA                                                                                  7752331D 80 Bytes  [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 7E                                                                                   7752399E 168 Bytes  [ 83, F8, 2C, 74, 7E, 66, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 128                                                                                  77523A48 2 Bytes  [ 48, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 12B                                                                                  77523A4B 22 Bytes  [ 6B, F2, 00, 00, 8D, 46, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 143                                                                                  77523A63 32 Bytes  [ 6A, 00, FF, 35, 00, 60, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 164                                                                                  77523A84 53 Bytes  JMP 775051B7 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsOle1Class + 22                                                                                     77524886 13 Bytes  [ 69, 00, 6E, 00, 73, 00, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 9                                                                                      77524894 120 Bytes  [ 6C, 00, 6C, 00, 00, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 82                                                                                     7752490D 190 Bytes  JMP 77503DA5 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 141                                                                                    775249CC 7 Bytes  [ 56, FF, 75, 08, 89, 45, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 149                                                                                    775249D4 159 Bytes  [ 15, 18, 18, 4B, 77, E9, 16, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 1E9                                                                                    77524A74 16 Bytes  [ 85, F6, 7C, 1A, 8D, 85, 7C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + 8F                                                                                   77524BD1 15 Bytes  [ 0F, B7, 70, 02, 8D, 74, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + 9F                                                                                   77524BE1 39 Bytes  [ CB, 8B, 1A, 8D, 7C, 7B, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + C7                                                                                   77524C09 2 Bytes  [ 45, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + CA                                                                                   77524C0C 4 Bytes  [ 4D, 10, 89, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + CF                                                                                   77524C11 48 Bytes  [ 08, 50, FF, 51, 04, 33, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 22                                                                                 77525276 24 Bytes  [ 85, DB, 0F, 84, C6, 6C, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 3B                                                                                 7752528F 30 Bytes  [ 00, 8D, 73, 04, A5, A5, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 5A                                                                                 775252AE 50 Bytes  [ 08, FF, 75, F8, FF, 15, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 8D                                                                                 775252E1 68 Bytes  [ 0F, 85, A3, 8C, 01, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + D2                                                                                 77525326 54 Bytes  [ 00, 56, FF, 75, 1C, 8B, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 23                                                                           77525762 37 Bytes  [ FF, 15, 24, 12, 4B, 77, 3D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 83                                                                           775257C2 7 Bytes  [ 0C, 89, 51, 04, 83, C1, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 8B                                                                           775257CA 63 Bytes  [ C0, 10, FF, 45, F4, 89, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + CB                                                                           7752580A 130 Bytes  [ 7F, 05, 02, 40, 00, 80, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 14E                                                                          7752588D 33 Bytes  [ 55, 8B, EC, 83, 7D, 08, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 2F                                                                              77526139 10 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 3A                                                                              77526144 18 Bytes  CALL 77526161 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 4D                                                                              77526157 50 Bytes  [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRun                                                                                                 7752618A 14 Bytes  [ 90, 90, 90, 90, 8B, FF, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRun + F                                                                                             77526199 129 Bytes  [ 3B, C7, 74, 15, 50, 57, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 4D                                                                                 7752621B 1 Byte  [ C0 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 4F                                                                                 7752621D 5 Bytes  [ 46, 14, 89, 46, 20 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 55                                                                                 77526223 18 Bytes  [ 46, 18, 89, 46, 24, 66, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 68                                                                                 77526236 186 Bytes  [ 46, 28, C7, 46, 30, 78, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 123                                                                                775262F1 167 Bytes  [ 1C, 00, 00, 00, 85, C0, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 2C                                                                                77526A8B 37 Bytes  [ 8B, 45, 08, 8B, 38, 8B, 58, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 53                                                                                77526AB2 50 Bytes  CALL 77526AC9 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 86                                                                                77526AE5 3 Bytes  [ 8D, 81, D0 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 8A                                                                                77526AE9 34 Bytes  [ 00, 00, 3B, 38, 74, 47, 42, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + AD                                                                                77526B0C 53 Bytes  [ 89, 41, 24, 8B, 74, C1, 28, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 2                                                                     77526D98 28 Bytes  [ 50, FF, 15, BC, 10, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 1F                                                                    77526DB5 3 Bytes  [ 00, 00, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 23                                                                    77526DB9 80 Bytes  [ 03, 46, 1C, 83, C0, 70, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 74                                                                    77526E0A 7 Bytes  JMP 7750FF7B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 7E                                                                    77526E14 5 Bytes  [ 8B, FF, 55, 8B, EC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + 19                                                             77526E9F 38 Bytes  [ 55, 8B, EC, 83, EC, 0C, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + 40                                                             77526EC6 109 Bytes  [ 77, 50, FF, 15, 24, 18, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + AE                                                             77526F34 25 Bytes  CALL 77526E2C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + C9                                                             77526F4F 31 Bytes  [ 8B, C7, 5F, 5E, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + EA                                                             77526F70 26 Bytes  [ C0, 89, 45, FC, 0F, 84, B5, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 16                                                                          77527127 41 Bytes  [ 35, 88, 18, 4B, 77, FF, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 41                                                                          77527152 2 Bytes  [ 71, 91 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 45                                                                          77527156 14 Bytes  [ 8B, 45, FC, 5F, 5E, 5B, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 54                                                                          77527165 1 Byte  [ 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 56                                                                          77527167 29 Bytes  [ EB, ED, 90, 90, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserUnmarshal + 14                                                                       77542EF3 40 Bytes  JMP 7750AC7E C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserUnmarshal + 3D                                                                       77542F1C 26 Bytes  [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 13                                                                         77542F38 16 Bytes  [ 74, 16, 64, A1, 18, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 24                                                                         77542F49 22 Bytes  [ 8E, 8C, 00, 00, 00, EB, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 3B                                                                         77542F60 113 Bytes  [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + AD                                                                         77542FD2 51 Bytes  CALL 77513779 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + E1                                                                         77543006 38 Bytes  CALL 7751F8DD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + 13                                                                            7754302E 28 Bytes  [ 4D, 08, 66, 83, B9, 82, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + 30                                                                            7754304B 92 Bytes  [ 8B, F0, 83, C0, F4, F7, DE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + AB                                                                            775430C6 20 Bytes  [ 66, 04, 00, 83, 26, 00, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + C2                                                                            775430DD 33 Bytes  [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + E4                                                                            775430FF 36 Bytes  [ 8B, CB, 89, 45, E4, E8, 80, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 19                                                                                       77544F16 11 Bytes  [ 89, 01, FF, 15, FC, 12, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 25                                                                                       77544F22 23 Bytes  [ 04, 8B, CE, EB, 2B, E8, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 3D                                                                                       77544F3A 6 Bytes  [ 75, F8, E8, F8, 07, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 44                                                                                       77544F41 177 Bytes  [ 8B, F8, 85, FF, 7C, 12, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + F6                                                                                       77544FF3 8 Bytes  [ 20, FF, 75, 1C, FF, 75, 18, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + 5A                                                                                  77545A6C 73 Bytes  [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + A4                                                                                  77545AB6 15 Bytes  [ 8D, 46, 04, 8B, 08, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + B4                                                                                  77545AC6 4 Bytes  [ DF, 03, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + BB                                                                                  77545ACD 15 Bytes  [ 11, 8B, 46, 30, 8B, 08, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + CB                                                                                  77545ADD 139 Bytes  [ 75, 24, 85, DB, 74, 20, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 1                                                                                   77545C50 10 Bytes  [ 7D, F4, 6A, 05, 59, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + D                                                                                   77545C5C 26 Bytes  [ F4, F3, A5, 8B, 08, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 28                                                                                  77545C77 3 Bytes  [ 74, 1D, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 2D                                                                                  77545C7C 37 Bytes  [ 8B, 43, 18, 8B, 08, 8D, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 53                                                                                  77545CA2 51 Bytes  [ 83, C3, 20, FF, 4D, EC, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 3B                                                                                 77545D44 56 Bytes  CALL 77523BEE C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 74                                                                                 77545D7D 23 Bytes  [ B8, FF, FF, FF, 7F, 80, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 8C                                                                                 77545D95 9 Bytes  [ C2, 0C, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 96                                                                                 77545D9F 27 Bytes  [ 55, 8B, EC, 83, 7D, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + B3                                                                                 77545DBC 3 Bytes  [ B5, DD, FD ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 3B                                                                                        7754720E 6 Bytes  [ 76, 8B, CB, E8, A2, CC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 42                                                                                        77547215 1 Byte  [ FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 45                                                                                        77547218 4 Bytes  [ 74, 6B, 83, 7E ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 4A                                                                                        7754721D 24 Bytes  [ FF, 74, 10, 83, 7D, 0C, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 63                                                                                        77547236 25 Bytes  [ FF, 75, 0C, 50, FF, 51, 58, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + 11                                                                                  7754743B 92 Bytes  [ 00, 00, 89, 86, AC, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + 6E                                                                                  77547498 89 Bytes  CALL 77525862 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + C9                                                                                  775474F3 37 Bytes  [ 8B, D8, EB, 13, 3B, C6, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + EF                                                                                  77547519 12 Bytes  [ 8D, 73, 30, 8B, 06, 56, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + FC                                                                                  77547526 56 Bytes  [ 45, 10, 25, 00, 02, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + AE                                                                                    77547972 38 Bytes  [ F8, FF, 3B, F3, 7D, 28, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + D5                                                                                    77547999 41 Bytes  [ BE, 1D, 01, 01, 80, EB, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + FF                                                                                    775479C3 124 Bytes  [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + 17C                                                                                   77547A40 71 Bytes  [ 56, 8B, 75, 10, 85, F6, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + 1C4                                                                                   77547A88 64 Bytes  CALL 7FA207DD 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 97                                                                                   77547C8C 66 Bytes  CALL 7759C5C2 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + DB                                                                                   77547CD0 6 Bytes  [ 11, 57, E8, 42, 67, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + E2                                                                                   77547CD7 39 Bytes  [ 85, C0, 75, 07, B8, 57, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 10A                                                                                  77547CFF 42 Bytes  [ C0, 74, 06, 8B, 08, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 135                                                                                  77547D2A 98 Bytes  [ 51, 50, FF, 52, 10, F6, 46, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 16                                                                                           77547F4A 261 Bytes  [ 50, FF, 51, 14, 85, C0, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 11C                                                                                          77548050 5 Bytes  [ BE, 80, 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 122                                                                                          77548056 58 Bytes  [ 07, 85, C0, 74, 09, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 15D                                                                                          77548091 33 Bytes  [ F6, 0F, 84, BB, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 17F                                                                                          775480B3 94 Bytes  [ 75, 0C, 83, 26, 00, E8, 5C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 3B                                                                                     775484CA 11 Bytes  [ DB, 74, 1D, 8D, 45, EC, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 47                                                                                     775484D6 5 Bytes  [ FF, FF, 75, E4, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 4D                                                                                     775484DC 8 Bytes  CALL 7751867C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 56                                                                                     775484E5 21 Bytes  [ EC, A5, A5, A5, A5, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 6C                                                                                     775484FB 102 Bytes  [ 4D, FC, 5F, 5E, 8B, C3, 5B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + 8C                                                                           775486C4 26 Bytes  CALL 7759D785 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + A7                                                                           775486DF 66 Bytes  [ 00, EB, 10, 6A, 01, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + EA                                                                           77548722 12 Bytes  [ 10, 53, FF, 75, 80, 8D, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + F7                                                                           7754872F 115 Bytes  [ 85, C0, 74, 4E, 8B, 45, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + 16B                                                                          775487A3 120 Bytes  [ 46, 34, 8B, 08, 50, FF, 51, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 44                                                                           7754898A 72 Bytes  CALL 77519C33 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 8D                                                                           775489D3 299 Bytes  [ C7, 41, 1C, 80, E1, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 1B9                                                                          77548AFF 75 Bytes  [ 50, FF, 51, 0C, 8B, D8, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 205                                                                          77548B4B 18 Bytes  [ 85, C0, 74, 11, 6A, 04, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 218                                                                          77548B5E 21 Bytes  [ 00, 00, 57, 8D, 7E, E4, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserFree + 6                                                                                   77548B74 18 Bytes  [ 08, 50, FF, 51, 14, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserFree + 19                                                                                  77548B87 65 Bytes  [ 44, 8B, 46, 2C, 8B, 08, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserUnmarshal + 31                                                                             77548BC9 1 Byte  [ 80 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserUnmarshal + 33                                                                             77548BCB 21 Bytes  [ 0C, 53, 83, C6, 40, 56, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 1                                                                           77548BE1 66 Bytes  [ C7, 5F, EB, 05, B8, 57, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 63                                                                          77548C43 49 Bytes  [ 00, 68, 78, 8C, 5D, 77, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 95                                                                          77548C75 5 Bytes  [ 89, 18, 8B, 03, 53 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 9B                                                                          77548C7B 10 Bytes  [ 50, 04, 8B, 03, 53, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + A6                                                                          77548C86 10 Bytes  [ B5, F4, FD, FF, FF, 8B, 03, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 20                                                                                  7754940A 7 Bytes  [ F0, 85, F6, 7C, 48, C7, 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 28                                                                                  77549412 66 Bytes  [ 01, 00, 00, 00, 8B, CB, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 6B                                                                                  77549455 27 Bytes  [ 50, 18, 8B, 4D, FC, E8, D5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 87                                                                                  77549471 103 Bytes  [ EC, 56, 8B, 75, 08, 57, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + EF                                                                                  775494D9 180 Bytes  [ 00, 39, 75, 08, 0F, 84, B1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 12                                                                                   7754958F 29 Bytes  [ 00, 33, F6, 5F, 5B, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 30                                                                                   775495AD 19 Bytes  [ 15, 50, 61, 5D, 77, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 44                                                                                   775495C1 36 Bytes  [ 55, 8B, EC, 53, 56, 8B, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalHresult + 1C                                                                                775495E6 85 Bytes  [ D7, 66, 85, C0, 7D, 31, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 2F                                                                                    7754963C 80 Bytes  [ EC, 53, 56, 57, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 80                                                                                    7754968D 22 Bytes  [ 45, 0C, 50, 57, FF, 76, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 97                                                                                    775496A4 13 Bytes  [ 33, 8D, 45, 0C, 50, 57, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + A5                                                                                    775496B2 429 Bytes  [ 25, 0F, B7, 45, 0C, 50, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 253                                                                                   77549860 151 Bytes  [ 75, 0C, 53, 68, 12, 01, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 7                                                                                      77549FAD 88 Bytes  [ 88, 50, 8D, 4B, FC, E8, 22, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 60                                                                                     7754A006 22 Bytes  [ 83, 63, 50, FE, B8, 71, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 77                                                                                     7754A01D 5 Bytes  [ 04, 80, E9, 2C, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 7E                                                                                     7754A024 59 Bytes  [ F6, 43, 50, 08, 0F, 85, 22, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + BA                                                                                     7754A060 56 Bytes  CALL 7759B8BD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 25                                                                             7754A625 15 Bytes  [ C0, 5D, C2, 04, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 35                                                                             7754A635 66 Bytes  [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 78                                                                             7754A678 47 Bytes  [ 00, 00, EB, 49, 66, 83, 3E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + A8                                                                             7754A6A8 2 Bytes  [ 2B, 09 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + AE                                                                             7754A6AE 210 Bytes  [ 89, 45, FC, 74, 12, 66, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 88                                                                                 7754A839 133 Bytes  [ 46, 0C, 6A, 00, 89, 45, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 10E                                                                                7754A8BF 65 Bytes  [ 06, 6A, 00, FF, 75, 0C, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 150                                                                                7754A901 63 Bytes  [ 7D, 08, 85, FF, 75, 04, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 190                                                                                7754A941 151 Bytes  [ 07, 57, FF, 15, 04, 12, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 228                                                                                7754A9D9 45 Bytes  [ C0, 75, 09, 66, 39, 46, 0A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 35                                                                                       7754B79B 5 Bytes  [ 90, 90, 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 3B                                                                                       7754B7A1 2 Bytes  [ FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 3E                                                                                       7754B7A4 14 Bytes  [ 7C, A7, 54, 77, 85, A7, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 4D                                                                                       7754B7B3 65 Bytes  [ 55, 8B, EC, 83, EC, 14, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 8F                                                                                       7754B7F5 61 Bytes  [ F0, 0F, 84, 53, 01, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 38                                                                                         7754B90C 81 Bytes  [ 15, 74, 12, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 8A                                                                                         7754B95E 28 Bytes  [ 18, 4B, 77, 85, C0, 75, 09, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + A7                                                                                         7754B97B 14 Bytes  [ FF, 55, 8B, EC, 56, 57, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + B6                                                                                         7754B98A 88 Bytes  [ 15, CC, 18, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 10F                                                                                        7754B9E3 8 Bytes  [ EB, DE, 90, 90, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx                                                                                    7754BDA1 30 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 1F                                                                               7754BDC0 18 Bytes  [ 83, 7E, 74, 01, 75, 07, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 32                                                                               7754BDD3 29 Bytes  [ 83, 38, 00, 74, 08, 8B, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 50                                                                               7754BDF1 72 Bytes  [ 5E, 5D, C2, 04, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 99                                                                               7754BE3A 100 Bytes  [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 2                                                                                  7754BE9F 21 Bytes  CALL 784243B3 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 18                                                                                 7754BEB5 18 Bytes  [ 53, 8D, 45, DC, 50, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 2B                                                                                 7754BEC8 21 Bytes  [ FF, 3B, C3, 89, 45, E8, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 41                                                                                 7754BEDE 39 Bytes  [ 75, E0, FF, 75, E0, FF, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 71                                                                                 7754BF0E 1 Byte  [ 4D ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreatePointerMoniker + 40                                                                              7754C3D8 200 Bytes  [ 00, 00, 8B, 4D, CC, 8D, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + A9                                                                               7754C4A1 3 Bytes  [ 07, 80, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + AD                                                                               7754C4A5 70 Bytes  [ B8, 3B, C3, 74, 06, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 119                                                                              7754C511 109 Bytes  [ 75, B4, 8B, 46, 04, 3B, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 187                                                                              7754C57F 212 Bytes  [ 08, 50, FF, 51, 08, 8B, C6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 25C                                                                              7754C654 27 Bytes  [ FF, 15, D0, 13, 4B, 77, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 36                                                                                       7754C732 32 Bytes  [ 51, C7, 01, 28, E0, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 57                                                                                       7754C753 19 Bytes  CALL 775A535B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 6B                                                                                       7754C767 30 Bytes  [ FF, 55, 8B, EC, 83, EC, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 8A                                                                                       7754C786 21 Bytes  [ 85, C0, 74, 11, 6A, 04, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + A0                                                                                       7754C79C 108 Bytes  [ 75, 30, 89, 3B, FF, 75, 2C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith                                                                                7754DE00 140 Bytes  [ 90, 6A, 0C, 68, 78, CE, 54, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + 8D                                                                           7754DE8D 38 Bytes  [ EC, 56, 57, 8B, 7D, 08, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + B4                                                                           7754DEB4 64 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + F5                                                                           7754DEF5 1 Byte  [ E0 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + F7                                                                           7754DEF7 7 Bytes  [ 35, 24, 12, 4B, 77, FF, D6 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 2                                                                         7754E98A 32 Bytes  [ 51, 44, 8B, D8, 3B, DF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 23                                                                        7754E9AB 10 Bytes  [ 45, FC, 8B, 4D, 0C, 89, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 2E                                                                        7754E9B6 91 Bytes  [ 02, 33, DB, 8B, 45, F8, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 8A                                                                        7754EA12 3 Bytes  [ 0C, 56, E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 8E                                                                        7754EA16 34 Bytes  [ FA, F7, FF, 85, C0, 0F, 84, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + 73                                                                                      7754EB1D 37 Bytes  [ 8B, 45, F4, 89, 45, F0, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + 99                                                                                      7754EB43 9 Bytes  [ 45, EC, 50, FF, 75, F8, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + A3                                                                                      7754EB4D 12 Bytes  [ FF, 8B, F8, 85, FF, 7C, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + B0                                                                                      7754EB5A 27 Bytes  [ 12, FF, 75, 10, FF, 75, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + CC                                                                                      7754EB76 40 Bytes  [ 75, F4, 50, FF, 51, 2C, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentLogicalThreadId                                                                            7755206E 50 Bytes  [ 90, 90, 90, 6A, 0C, 68, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 43                                                                                 775520E8 48 Bytes  [ 75, 14, 33, C0, F3, A7, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 74                                                                                 77552119 44 Bytes  [ 04, 83, C6, 14, 89, 33, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 17A                                                                                7755221F 33 Bytes  [ 50, FF, 11, 89, 45, E4, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 19C                                                                                77552241 41 Bytes  [ 51, 08, EB, 21, C7, 45, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 1F9                                                                                7755229E 50 Bytes  [ 49, 18, 8B, 55, 0C, 89, 0A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 3                                                                                     7755269F 73 Bytes  [ 77, 78, 16, 55, 77, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 56                                                                                    775526F2 26 Bytes  [ 8B, FF, 55, 8B, EC, 5D, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 71                                                                                    7755270D 15 Bytes  [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 82                                                                                    7755271E 58 Bytes  [ 90, 90, 90, 83, 6C, 24, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + BD                                                                                    77552759 98 Bytes  [ EB, A7, 90, 90, 90, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 1C                                                                                 77552973 3 Bytes  [ E0, FE, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 20                                                                                 77552977 9 Bytes  [ 89, 45, CC, 33, F6, 3B, C6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 2A                                                                                 77552981 100 Bytes  [ 00, 00, 00, 8B, 4D, D0, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 33                                                                           775529E6 38 Bytes  [ FF, 89, 45, CC, 3B, C6, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 5A                                                                           77552A0D 37 Bytes  [ 7C, 40, 8B, 45, C0, 2B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 80                                                                           77552A33 112 Bytes  [ 04, 80, EB, 1F, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + F1                                                                           77552AA4 3 Bytes  [ C8, 10, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + F5                                                                           77552AA8 30 Bytes  [ 00, 8B, 7D, 0C, 8B, 07, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 52                                                                             77552B9F 29 Bytes  [ 01, 04, 80, EB, 18, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 70                                                                             77552BBD 9 Bytes  [ 4D, FC, FF, 8B, 45, D0, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 7A                                                                             77552BC7 3 Bytes  [ B5, B7, F7 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState                                                                                             77552BD4 51 Bytes  [ 90, 90, 90, 90, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState + 34                                                                                        77552C08 14 Bytes  [ 45, 18, 89, 18, C7, 45, B4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState + 43                                                                                        77552C17 91 Bytes  [ 08, 8D, 55, B4, 52, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 4A                                                                              77552C73 156 Bytes  [ D0, 8D, 43, 02, 83, C0, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + E7                                                                              77552D10 47 Bytes  [ 10, D1, FF, 8B, 45, 14, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 11C                                                                             77552D45 17 Bytes  CALL CF397311 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 137                                                                             77552D60 123 Bytes  [ FF, FF, FF, FF, 3B, 1D, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 1B3                                                                             77552DDC 55 Bytes  [ 90, 90, 90, 90, 90, B8, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 24                                                                               77552E63 4 Bytes  [ 75, 07, B8, 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 29                                                                               77552E68 64 Bytes  [ 07, 80, EB, 43, 83, 7D, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 6A                                                                               77552EA9 52 Bytes  [ C6, EB, 03, 33, C0, 40, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 9F                                                                               77552EDE 16 Bytes  [ FF, 75, 08, FF, 15, D0, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + B0                                                                               77552EEF 27 Bytes  [ 06, FF, 75, 10, 8B, CE, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 1                                                                                  77552F10 258 Bytes  [ EC, 8B, 45, 08, 51, 68, BA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 104                                                                                77553013 4 Bytes  [ FF, 55, 8B, EC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 11D                                                                                7755302C 46 Bytes  [ 07, 80, 5D, C2, 08, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 20B                                                                                7755311A 48 Bytes  [ 51, 08, 5F, 8B, C6, 5E, 5B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 23D                                                                                7755314C 24 Bytes  [ 00, 75, 20, 6A, 48, E8, 7B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 5F                                                                               77553764 18 Bytes  [ BF, 28, 6C, 4C, 77, 57, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 72                                                                               77553777 6 Bytes  [ 01, 56, 53, FF, 75, 94 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 79                                                                               7755377E 13 Bytes  [ 15, 2C, 10, 4B, 77, 8B, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 87                                                                               7755378C 122 Bytes  [ 00, 8D, 45, 8C, 50, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 102                                                                              77553807 133 Bytes  [ 15, 40, 10, 4B, 77, 33, F6, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject                                                                                       7755398C 167 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + A8                                                                                  77553A34 18 Bytes  [ 00, 3B, F3, 75, 3F, 6A, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + BB                                                                                  77553A47 2 Bytes  [ 45, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + BE                                                                                  77553A4A 34 Bytes  [ 80, 08, 01, 00, 00, 89, 46, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + E1                                                                                  77553A6D 17 Bytes  [ F7, FF, C7, 45, 0C, 0E, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 65                                                                                 77554626 61 Bytes  [ FF, 55, 8B, EC, FF, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + A3                                                                                 77554664 58 Bytes  [ 07, 80, EB, 31, 57, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + DF                                                                                 775546A0 85 Bytes  [ 90, 90, 90, A1, A8, C5, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 135                                                                                775546F6 9 Bytes  [ E0, B8, 02, 40, 00, 80, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 13F                                                                                77554700 8 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDeactivateObject + 5A                                                                                7755489F 65 Bytes  [ 0F, 85, C3, 00, 00, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 9                                                                                 775548E1 39 Bytes  CALL C85548E4 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 31                                                                                77554909 33 Bytes  [ 74, 5D, 56, 8B, 35, 28, 12, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 53                                                                                7755492B 28 Bytes  [ D6, 68, F0, 8A, 4C, 77, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 70                                                                                77554948 106 Bytes  [ 77, A3, AC, C5, 5D, 77, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInvalidateRemoteMachineBindings + 2                                                                  775549B3 5 Bytes  [ FF, 00, 80, 5D, C2 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInvalidateRemoteMachineBindings + 9                                                                  775549BA 35 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRetireServer + 9                                                                                     775549DE 20 Bytes  [ 72, 5D, 77, 8B, F0, 8D, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRetireServer + 1E                                                                                    775549F3 9 Bytes  [ 75, 16, 83, C6, 08, 3B, F0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetContextToken + 1                                                                                  77554A25 40 Bytes  [ 48, 0C, 83, C0, 20, 3B, C8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetContextToken + 2A                                                                                 77554A4E 55 Bytes  [ 4D, FC, 6A, 01, 83, C1, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetSystemSecurityPermissions + 2B                                                                    77554A86 14 Bytes  [ 60, 5D, 77, FF, 15, 54, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetSystemSecurityPermissions + 3A                                                                    77554A95 77 Bytes  [ 75, 0C, 89, 43, 0C, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 3A                                                                               77554AE3 77 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 89                                                                               77554B32 33 Bytes  [ 00, 53, 56, 89, 45, FC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + AB                                                                               77554B54 27 Bytes  [ FF, 50, FF, 15, C0, 18, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + C7                                                                               77554B70 23 Bytes  [ CB, 89, 85, EC, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 10D                                                                              77554BB6 8 Bytes  [ FF, 50, 57, 8B, CE, E8, 86, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCancelObject + 7B                                                                                 775550ED 79 Bytes  [ FF, 55, 8B, EC, 68, A8, BA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCancelCall + 35                                                                                      7755513D 49 Bytes  [ FF, 55, 8B, EC, 56, 68, AC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTestCancel + 27                                                                                      7755516F 2 Bytes  [ FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTestCancel + 2A                                                                                      77555172 71 Bytes  [ EC, 56, 68, B0, BA, 5D, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoEnableCallCancellation + 39                                                                          775551BA 5 Bytes  [ 25, B8, BA, 5D, 77 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoEnableCallCancellation + 40                                                                          775551C1 1 Byte  [ 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 5                                                                          775551CD 80 Bytes  [ 68, BC, BA, 5D, 77, 68, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 56                                                                         7755521E 19 Bytes  [ F0, 8B, C6, 5E, 5D, C2, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 6A                                                                         77555232 3 Bytes  [ E4, BA, 5D ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 6E                                                                         77555236 6 Bytes  [ 68, 70, 8C, 4C, 77, 33 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 81                                                                         77555249 6 Bytes  [ FF, 75, 0C, FF, 75, 08 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 8                                                                                  77555626 122 Bytes  [ 08, 50, FF, 51, 04, EB, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 83                                                                                 775556A1 19 Bytes  [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 97                                                                                 775556B5 10 Bytes  [ 08, 50, FF, 51, 0C, EB, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + A2                                                                                 775556C0 41 Bytes  [ 80, 5D, C2, 08, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + CC                                                                                 775556EA 269 Bytes  [ 80, 5D, C2, 08, 00, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + 37                                                                     775558A8 113 Bytes  [ 8B, 06, 56, FF, 50, 08, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + A9                                                                     7755591A 22 Bytes  [ 00, 8B, F0, 8B, 45, 0C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + C0                                                                     77555931 37 Bytes  [ 08, 50, FF, 51, 08, EB, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + E6                                                                     77555957 24 Bytes  [ 57, 8B, 7D, 08, 33, F6, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + FF                                                                     77555970 29 Bytes  [ 07, 8D, 4D, FC, 51, 68, 18, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 29                                                                           77559AAD 2 Bytes  [ 0E, 47 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 2D                                                                           77559AB1 188 Bytes  [ 39, 7D, F0, 0F, 84, BB, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + EA                                                                           77559B6E 27 Bytes  [ F7, FF, 39, 7D, FC, 7D, 65, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 107                                                                          77559B8B 6 Bytes  [ 45, EC, 3B, C7, 74, 0F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 10E                                                                          77559B92 36 Bytes  [ 08, 50, FF, 51, 10, 8B, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + BA                                                                                  7755B46D 34 Bytes  [ 08, 83, 65, F8, 00, 8D, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + DD                                                                                  7755B490 42 Bytes  [ 51, 10, 8B, F0, 8B, 45, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 108                                                                                 7755B4BB 26 Bytes  [ 8B, 45, F4, 83, C0, 07, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 123                                                                                 7755B4D6 12 Bytes  [ 8D, 6E, FF, FF, FF, 85, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 130                                                                                 7755B4E3 54 Bytes  [ 4D, FC, 89, 08, 8B, C6, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterPSClsid + 94                                                                                 7755C75C 34 Bytes  [ 8B, F0, 85, F6, 0F, 8C, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPushServiceDomain + 13                                                                               7755C77F 51 Bytes  [ FF, 8B, F0, 85, F6, 0F, 8C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + C                                                                                 7755C7B3 20 Bytes  [ 89, 55, E0, 89, 7D, E4, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 21                                                                                7755C7C8 66 Bytes  [ 15, FC, 12, 4B, 77, 57, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 64                                                                                7755C80B 18 Bytes  [ 50, 10, 8B, F0, 8B, 45, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 77                                                                                7755C81E 35 Bytes  [ 45, B4, 8B, 40, 24, 57, 23, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 9B                                                                                7755C842 8 Bytes  [ 4D, B4, 8D, 45, 9C, 89, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 4F                                                                             7755E25D 4 Bytes  [ 68, 30, 75, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 54                                                                             7755E262 31 Bytes  [ FF, 76, 30, FF, D7, BB, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 74                                                                             7755E282 3 Bytes  [ 00, 00, 51 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 79                                                                             7755E287 137 Bytes  [ 15, A8, 10, 4B, 77, B9, CC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 104                                                                            7755E312 148 Bytes  [ 68, 20, 4E, 00, 00, FF, 76, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 10                                                                                7755F5A2 66 Bytes  [ 40, 18, 83, 65, FC, 00, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 53                                                                                7755F5E5 41 Bytes  [ 15, 34, 12, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 7D                                                                                7755F60F 28 Bytes  [ 55, 8B, EC, 8B, 45, 08, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 9A                                                                                7755F62C 43 Bytes  [ 15, 24, 12, 4B, 77, 0D, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + C6                                                                                7755F658 27 Bytes  [ 09, 89, 48, 14, 33, C0, EB, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 8A                                                                               775661D6 1 Byte  [ 4A ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 8D                                                                               775661D9 8 Bytes  [ 0C, 8B, 4F, 10, E8, 3B, E2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 96                                                                               775661E2 8 Bytes  [ 8B, CE, 8B, D8, E8, D4, 7F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 9F                                                                               775661EB 60 Bytes  [ 85, DB, 7C, 1F, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromIStorage + B                                                                          77566228 49 Bytes  [ 8B, 45, 14, 8B, 4D, FC, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLoadLibrary + 13                                                                                     7756625A 55 Bytes  [ 77, 00, 75, 51, 33, FF, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + E2                                                                                         775663C9 3 Bytes  [ 21, 34, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + E6                                                                                         775663CD 6 Bytes  [ FF, 75, 08, 83, 66, 14 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + ED                                                                                         775663D4 67 Bytes  [ FF, 75, 08, 8B, CE, E8, 67, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + 131                                                                                        77566418 140 Bytes  [ 3B, 89, 4B, 14, 8B, 36, F3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + 1BE                                                                                        775664A5 40 Bytes  [ 50, FF, 15, 40, 12, 4B, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeToDosDateTime + 78                                                                           7756B0CF 64 Bytes  [ FD, FF, FF, 00, 8D, 8D, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 3D                                                                           7756B110 38 Bytes  [ 02, 00, 00, B9, 82, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 64                                                                           7756B137 42 Bytes  [ 15, 84, 13, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 8F                                                                           7756B162 27 Bytes  [ 00, 8D, 44, 00, 18, 50, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + AB                                                                           7756B17E 2 Bytes  [ 51, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + AF                                                                           7756B182 2 Bytes  [ DC, 14 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 10                                                                                  7757016C 51 Bytes  [ 90, 8B, FF, 55, 8B, EC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 44                                                                                  775701A0 305 Bytes  [ 8B, 08, 68, A4, FF, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 176                                                                                 775702D2 23 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 18E                                                                                 775702EA 104 Bytes  [ FF, 75, 10, 8B, 08, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 1F7                                                                                 77570353 20 Bytes  [ 00, 74, 11, FF, 75, 10, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_QueryInterface                                                                    77570529 5 Bytes  [ 90, 90, 90, 90, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_QueryInterface + 6                                                                7757052F 113 Bytes  [ 55, 8B, EC, 51, 53, 56, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 2                                                     775705A1 3 Bytes  [ 8B, 45, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 6                                                     775705A5 18 Bytes  [ 08, 89, 4F, 08, 89, 38, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 1C                                                    775705BB 116 Bytes  [ 8B, FF, 55, 8B, EC, 51, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_CountRefs + 7                                                                     77570631 5 Bytes  [ FC, 8B, 08, 89, 4F ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_CountRefs + D                                                                     77570637 21 Bytes  [ 89, 38, 8B, 3F, 3B, FB, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 9                                                                    7757064D 33 Bytes  [ EC, 56, 57, 8B, 7D, 08, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 2B                                                                   7757066F 1 Byte  [ 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 56                                                                   7757069A 65 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 98                                                                   775706DC 53 Bytes  [ 55, 14, 85, D2, 74, 14, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + CE                                                                   77570712 14 Bytes  [ 40, 1C, 8B, 40, 24, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 25                                                                      77570953 86 Bytes  JMP 02FCFC5A 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 7C                                                                      775709AA 100 Bytes  [ 46, FC, 50, 8B, 46, 18, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + E1                                                                      77570A0F 47 Bytes  [ 8D, 8D, 6C, FF, FF, FF, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 120                                                                     77570A4E 12 Bytes  [ 51, 08, 83, 65, E4, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 12F                                                                     77570A5D 29 Bytes  [ 8B, 47, 08, 89, 45, 80, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + F                                                                            775745F4 99 Bytes  [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + A6                                                                           7757468B 24 Bytes  [ 90, 90, 90, 90, 90, B8, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 100                                                                          775746E5 13 Bytes  [ 90, 90, 90, 90, 90, B8, 07, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 10E                                                                          775746F3 174 Bytes  [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 1F0                                                                          775747D5 23 Bytes  [ 90, 90, 90, 90, 90, B8, 17, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 1B                                                                              77574AA8 206 Bytes  [ 90, 90, B8, 47, 03, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + EA                                                                              77574B77 14 Bytes  [ 90, 90, 90, 90, 90, B8, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + F9                                                                              77574B86 63 Bytes  [ 90, 90, 90, 90, 90, B8, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 13A                                                                             77574BC7 41 Bytes  [ B8, 5A, 03, 00, 00, E9, CC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 167                                                                             77574BF4 25 Bytes  [ B8, 5D, 03, 00, 00, E9, 9F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject                                                                             775751D0 98 Bytes  [ B8, C1, 03, 00, 00, E9, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 63                                                                        77575233 14 Bytes  [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 72                                                                        77575242 31 Bytes  [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 93                                                                        77575263 71 Bytes  [ 90, 90, 90, B8, CB, 03, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + DB                                                                        775752AB 15 Bytes  [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllUnregisterProxy + 6                                                                        77575F1A 31 Bytes  [ FF, F6, 45, 08, 01, 74, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllUnregisterProxy + 61                                                                       77575F75 54 Bytes  [ 8B, FF, 55, 8B, EC, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 34                                                                                77575FAC 41 Bytes  [ 5D, 0C, 85, DB, 56, 57, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 5E                                                                                77575FD6 19 Bytes  [ 5B, 5D, C2, 0C, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 8E                                                                                77576006 15 Bytes  [ 51, 0C, 5E, 5D, C2, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 9E                                                                                77576016 61 Bytes  [ EC, 56, 8B, 75, 08, 56, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + DC                                                                                77576054 12 Bytes  [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserSize + 57                                                                                  77589980 137 Bytes  [ A1, 04, 60, 5D, 77, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + 61                                                                               77589A0A 66 Bytes  [ 32, 02, 00, 00, 8D, 85, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + A4                                                                               77589A4D 50 Bytes  CALL 7758991A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + D7                                                                               77589A80 23 Bytes  [ 85, 7C, FB, FF, FF, 89, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + EF                                                                               77589A98 95 Bytes  [ F4, 6C, 4C, 77, BE, A8, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + 14F                                                                              77589AF8 49 Bytes  [ FF, 68, 28, 99, 4C, 77, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + B                                                                              77589B44 36 Bytes  CALL 77589719 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 30                                                                             77589B69 5 Bytes  [ 89, 85, 50, FB, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 36                                                                             77589B6F 6 Bytes  [ 68, C0, 98, 4C, 77, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 3D                                                                             77589B76 87 Bytes  [ D6, 8B, 85, 7C, FB, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 95                                                                             77589BCE 51 Bytes  CALL 77589719 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserFree + 34                                                                            77589D4C 17 Bytes  [ 10, 4B, 77, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserFree + 46                                                                            77589D5E 42 Bytes  [ B5, 74, FB, FF, FF, FF, D6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserUnmarshal + 11                                                                        77589D89 177 Bytes  [ FF, FF, FF, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + C                                                                              77589E3B 10 Bytes  CALL 775898B9 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 17                                                                             77589E46 66 Bytes  [ 5B, 18, 3B, DE, 74, 40, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 5A                                                                             77589E89 33 Bytes  [ 50, EB, 05, 68, 6C, EE, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 7D                                                                             77589EAC 60 Bytes  [ 00, 33, C0, 8B, 4D, E4, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserUnmarshal + 12                                                                           77589EE9 134 Bytes  [ 8B, 00, 8B, 70, 14, 6A, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserUnmarshal + 99                                                                           77589F70 88 Bytes  [ 10, FD, FF, FF, 33, DB, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserSize + 2                                                                                  77589FC9 144 Bytes  JMP 7758A89A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 4B                                                                              7758A05A 111 Bytes  [ B5, 14, FD, FF, FF, E8, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + BB                                                                              7758A0CA 83 Bytes  [ 89, 8D, 5C, FC, FF, FF, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 10F                                                                             7758A11E 109 Bytes  [ 15, 20, 14, 4B, 77, 8D, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 17D                                                                             7758A18C 10 Bytes  [ 0F, 84, 26, 01, 00, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 189                                                                             7758A198 150 Bytes  JMP 7758A26D C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserUnmarshal + B                                                                             7758A22F 39 Bytes  [ FF, FF, 15, 40, 10, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserUnmarshal + 33                                                                            7758A257 20 Bytes  [ EB, 06, 8B, 3D, 24, 12, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserFree + 2                                                                                   7758A26C 40 Bytes  [ FF, FF, 15, 40, 10, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 1                                                                                       7758A295 21 Bytes  [ 85, 10, FD, FF, FF, FF, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 17                                                                                      7758A2AB 1 Byte  [ FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 19                                                                                      7758A2AD 9 Bytes  [ BE, 6C, EE, 4B, 77, 8B, 3D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 24                                                                                      7758A2B8 38 Bytes  [ 89, 9D, A0, FC, FF, FF, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 2                                                                                    7758A2DF 63 Bytes  [ 89, 9D, FC, FC, FF, FF, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 42                                                                                   7758A31F 5 Bytes  [ 4B, 77, 89, 85, CC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 48                                                                                   7758A325 3 Bytes  [ FF, FF, 3B ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 4C                                                                                   7758A329 81 Bytes  [ 75, 31, FF, B5, E4, FC, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 2                                                                                  7758A37B 15 Bytes  [ D7, 25, FF, FF, 00, 00, 0D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 12                                                                                 7758A38B 171 Bytes  [ 39, 9D, FC, FC, FF, FF, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + BE                                                                                 7758A437 63 Bytes  [ C8, FC, FF, FF, 3B, C3, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + FE                                                                                 7758A477 69 Bytes  [ B5, F4, FC, FF, FF, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 145                                                                                7758A4BE 4 Bytes  [ 89, 85, 60, FC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 2                                                                                       7758A4DD 23 Bytes  [ FF, 50, 8D, 85, 0C, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 1A                                                                                      7758A4F5 78 Bytes  [ B5, 18, FD, FF, FF, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 6B                                                                                      7758A546 11 Bytes  [ 15, 40, 10, 4B, 77, FF, D7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 77                                                                                      7758A552 154 Bytes  [ D7, EB, 0C, FF, D7, 25, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 112                                                                                     7758A5ED 70 Bytes  [ B5, 18, FD, FF, FF, FF, 15, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLockRunning + D                                                                                     77598833 8 Bytes  [ 77, 3B, C3, 0F, 84, C1, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLockRunning + 16                                                                                    7759883C 131 Bytes  [ 66, 8B, 48, 02, 0F, B7, D1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetContainedObject + 4E                                                                             775988CA 159 Bytes  [ FF, B6, 84, 00, 00, 00, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + 9C                                                                              7759896B 11 Bytes  [ 50, FF, 11, 3B, C3, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + AA                                                                              77598979 53 Bytes  [ 8B, 45, F8, FF, 37, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + E0                                                                              775989AF 12 Bytes  [ FF, 89, 45, FC, EB, 4F, 39, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + ED                                                                              775989BC 135 Bytes  CALL 77595733 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + 175                                                                             77598A44 9 Bytes  [ 10, 8B, F1, FF, 15, 74, 12, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetDocumentBitStg                                                                                      77598BC1 47 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetDocumentBitStg + B                                                                                  77598BF1 34 Bytes  [ 83, C1, 08, 3B, CA, 72, F4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetConvertStg                                                                                          77598C14 44 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 1                                                                                            77598C41 108 Bytes  [ F0, EB, 02, 33, F6, 3B, F3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 6E                                                                                           77598CAE 91 Bytes  [ 08, 8D, 5E, 20, 53, 68, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + CA                                                                                           77598D0A 29 Bytes  [ 33, DB, 8B, 46, 1C, 8B, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + E8                                                                                           77598D28 105 Bytes  [ 30, 89, 5D, 10, 8B, 45, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 152                                                                                          77598D92 106 Bytes  [ 7E, 3C, 89, 45, FC, 8B, 07, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 75                                                                                  77598F77 6 Bytes  [ EB, 0A, C7, 85, 00, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 7C                                                                                  77598F7E 24 Bytes  [ FF, 0E, 00, 07, 80, 85, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 121                                                                                 77599023 19 Bytes  [ 04, FF, FF, FF, 00, EB, 12, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 135                                                                                 77599037 8 Bytes  [ 15, D8, 13, 4B, 77, 0F, B7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 13E                                                                                 77599040 21 Bytes  [ 8D, 00, FF, FF, FF, C1, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData                                                                                7759968A 78 Bytes  [ 90, 8B, FF, 55, 8B, EC, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 4F                                                                           775996D9 29 Bytes  [ 0D, 8B, 45, 10, 83, 20, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 6D                                                                           775996F7 5 Bytes  [ 5F, 5E, 5D, C2, 0C ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 73                                                                           775996FD 16 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 84                                                                           7759970E 246 Bytes  [ 85, C0, 74, 12, 8B, 55, 08, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkEx + 7C                                                                                   77599B6A 130 Bytes  [ 4D, FC, 51, 57, 6A, 10, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 21                                                                             77599BED 45 Bytes  [ 0C, F7, D8, 1B, C0, 83, E0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 4F                                                                             77599C1B 31 Bytes  [ 08, 50, 8B, 45, 08, E8, 22, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 6F                                                                             77599C3B 20 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 84                                                                             77599C50 14 Bytes  [ 85, C0, 75, 07, BE, 57, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 93                                                                             77599C5F 4 Bytes  [ 14, 74, 18, E8 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + E                                                                                77599D9E 42 Bytes  [ E1, 03, F3, A4, 8B, 4D, DC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 39                                                                               77599DC9 4 Bytes  [ 4D, 20, 8B, 11 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 3E                                                                               77599DCE 2 Bytes  [ 50, 20 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 41                                                                               77599DD1 78 Bytes  [ 49, 04, 89, 48, 24, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 90                                                                               77599E20 6 Bytes  [ 56, 8D, 8D, F0, FE, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 4                                                                                      7759A0B4 2 Bytes  [ 08, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 7                                                                                      7759A0B7 2 Bytes  [ 51, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + A                                                                                      7759A0BA 36 Bytes  [ 45, E4, 85, C0, 74, 06, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 2F                                                                                     7759A0DF 53 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 1A                                                                               7759A115 20 Bytes  [ 0D, FF, B5, E4, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 2F                                                                               7759A12A 22 Bytes  CALL C859A12C 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 46                                                                               7759A141 6 Bytes  [ 00, 8D, 85, FC, FD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 2                                                                                  7759A148 40 Bytes  CALL C859A14A 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 86                                                                                 7759A1CC 7 Bytes  [ 33, C9, 41, 3B, C1, 75, 64 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 8E                                                                                 7759A1D4 123 Bytes  [ 75, 0C, 3B, F7, 74, 48, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 10A                                                                                7759A250 12 Bytes  [ 55, 8B, EC, 56, 33, F6, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 117                                                                                7759A25D 3 Bytes  [ 45, 08, 8B ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 4                                                                                    7759BFBF 27 Bytes  [ 4E, 58, 8D, 45, F8, 50, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 20                                                                                   7759BFDB 51 Bytes  [ 24, 83, 78, 1C, FF, 75, 1E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 55                                                                                   7759C010 7 Bytes  [ 8B, C7, F7, D0, 21, 46, 68 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 5D                                                                                   7759C018 1 Byte  [ 5D ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 5F                                                                                   7759C01A 8 Bytes  [ 74, 08, 57, 8B, CE, E8, EA, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 37                                                                                        775A03D8 18 Bytes  [ 8B, F8, 85, FF, 0F, 85, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 4A                                                                                        775A03EB 71 Bytes  [ 05, 9B, 00, 00, 8B, F8, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 92                                                                                        775A0433 36 Bytes  [ 8B, F8, 83, 3B, 08, 75, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + B7                                                                                        775A0458 12 Bytes  [ F8, 8B, 06, 89, 41, 08, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + C4                                                                                        775A0465 6 Bytes  [ 51, 08, 83, 65, A4, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEmbeddingHelper + 3A                                                                          775A1AC9 9 Bytes  [ 0C, 0F, 94, C1, 8B, C1, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEmbeddingHelper + 44                                                                          775A1AD3 398 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + 6C                                                                                 775A1C62 25 Bytes  [ 76, 3C, FF, 75, F0, FF, D3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + 86                                                                                 775A1C7C 30 Bytes  [ D3, A8, 03, 74, 4F, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + A5                                                                                 775A1C9B 50 Bytes  [ 15, A8, 17, 4B, 77, 83, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + D8                                                                                 775A1CCE 12 Bytes  [ FF, FF, 83, 7D, 08, 00, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + E5                                                                                 775A1CDB 30 Bytes  [ 00, 00, 33, C0, 40, 5B, 5F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 1A                                                                   775A2759 15 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 2A                                                                   775A2769 66 Bytes  CALL 77503EB6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 6D                                                                   775A27AC 45 Bytes  [ 0F, 94, C1, 51, 56, FF, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 9B                                                                   775A27DA 75 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + E7                                                                   775A2826 23 Bytes  [ 85, C0, 75, 07, B8, 0E, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + A                                                                                   775A2C01 92 Bytes  [ A1, 04, 60, 5D, 77, 83, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 67                                                                                  775A2C5E 2 Bytes  [ FC, FB ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 78                                                                                  775A2C6F 17 Bytes  [ 50, FF, 15, 20, 14, 4B, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 8A                                                                                  775A2C81 34 Bytes  [ B8, EF, 4B, 77, FF, B5, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + AD                                                                                  775A2CA4 5 Bytes  [ FF, 00, 5B, 74, 0C ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + 57                                                                                 775A2F38 24 Bytes  [ F6, 74, 07, 33, F6, E9, 46, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + 71                                                                                 775A2F52 58 Bytes  [ 15, 7C, 13, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + AC                                                                                 775A2F8D 7 Bytes  [ FF, 8D, 85, 7C, FF, FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + B4                                                                                 775A2F95 9 Bytes  [ FF, 15, 78, 12, 4B, 77, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + BE                                                                                 775A2F9F 2 Bytes  [ FF, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 2D                                                                               775A3D7E 15 Bytes  [ FF, FF, D3, 8D, 85, 88, FA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 3D                                                                               775A3D8E 117 Bytes  [ 50, FF, 35, 2C, 61, 5D, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + B3                                                                               775A3E04 97 Bytes  [ FA, FF, FF, 8D, 44, 46, FE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 115                                                                              775A3E66 12 Bytes  [ 50, 8D, 85, 54, FF, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 122                                                                              775A3E73 10 Bytes  [ 68, 00, 00, 00, 80, C7, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 29                                                                     775A9645 17 Bytes  [ 55, 8B, EC, 81, EC, AC, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 3B                                                                     775A9657 3 Bytes  [ 53, 33, DB ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 3F                                                                     775A965B 1 Byte  [ 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 41                                                                     775A965D 91 Bytes  [ 52, 53, 53, 89, 45, FC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + 42                                                                   775A96B9 148 Bytes  [ 75, B4, FF, 15, 20, 14, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + D7                                                                   775A974E 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + D9                                                                   775A9750 9 Bytes  [ 5D, B0, 6A, 04, 33, C0, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + E3                                                                   775A975A 3 Bytes  [ B2, EF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + E9                                                                   775A9760 9 Bytes  [ 89, 45, AC, 0F, 8C, 01, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 14                                                                     775A9976 59 Bytes  CALL 775917AD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 50                                                                     775A99B2 14 Bytes  [ 55, 8B, EC, 83, 7D, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 5F                                                                     775A99C1 69 Bytes  [ 00, 8B, 03, 85, C0, 75, 0A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4                                                                    775A9A07 14 Bytes  [ F8, 85, FF, 75, 07, B8, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4B                                                                   775A9A4E 2 Bytes  [ D2, 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4F                                                                   775A9A52 30 Bytes  [ 8B, C6, 5E, 5F, 5D, C2, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 6E                                                                   775A9A71 5 Bytes  [ FF, 85, C0, 74, 09 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 74                                                                   775A9A77 160 Bytes  CALL 775A8CE0 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd16Info + 1B                                                                                   775AA719 205 Bytes  [ F0, 85, F6, 0F, 85, B8, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd16Info + 113                                                                                  775AA811 30 Bytes  [ 85, C0, 0F, 8C, 12, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 8                                                                            775AA830 148 Bytes  [ FF, 03, 75, 0F, 8B, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 9D                                                                           775AA8C5 25 Bytes  [ 01, 75, 4B, 83, 65, F8, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + B7                                                                           775AA8DF 68 Bytes  CALL 775A99AF C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + FC                                                                           775AA924 45 Bytes  CALL 775AA306 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 12A                                                                          775AA952 63 Bytes  CALL 775AA7F6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1                                                                                    775AAA1A 5 Bytes  [ 45, 0C, 89, 45, 94 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 7                                                                                    775AAA20 20 Bytes  [ 45, 10, 53, 8B, 5D, 1C, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1C                                                                                   775AAA35 1 Byte  [ 7D ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1E                                                                                   775AAA37 9 Bytes  [ 8D, 4D, A8, 89, 45, 98, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 28                                                                                   775AAA41 75 Bytes  [ E2, FF, FF, 39, 75, A0, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 30                                                                           775AAB59 150 Bytes  [ 4E, 1C, 8B, 55, 9C, 89, 0A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + FD                                                                           775AAC26 41 Bytes  [ 06, 56, FF, 50, 0C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 127                                                                          775AAC50 18 Bytes  [ 6A, 01, FF, 75, F0, E8, A0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 13A                                                                          775AAC63 71 Bytes  [ F8, 7F, 05, 0E, 00, 07, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 182                                                                          775AACAB 4 Bytes  [ 8B, 45, EC, 83 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 3F                                                                        775AC07F 19 Bytes  [ 15, 00, 12, 4B, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 53                                                                        775AC093 174 Bytes  [ 00, 50, 6A, 02, FF, 15, D0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 102                                                                       775AC142 21 Bytes  [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 118                                                                       775AC158 180 Bytes  [ 89, 5D, F8, 89, 5D, E8, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 1CD                                                                       775AC20D 28 Bytes  [ 15, 94, 11, 4B, 77, 89, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 10                                                                            775AC3A5 9 Bytes  [ 1F, 39, 5D, FC, 74, 09, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 1A                                                                            775AC3AF 110 Bytes  [ 15, CC, 13, 4B, 77, 39, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 89                                                                            775AC41E 125 Bytes  [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 107                                                                           775AC49C 9 Bytes  [ 99, F7, 7E, 18, 8B, 4D, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 111                                                                           775AC4A6 27 Bytes  [ 46, 08, 69, C0, A0, 86, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantChangeType + 32                                                                             775B3A19 118 Bytes  [ 0E, 00, 07, 80, EB, 13, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantChangeType + A9                                                                             775B3A90 30 Bytes  [ 45, 08, 83, C0, 08, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + 2                                                                                 775B3AAF 11 Bytes  [ 8B, F0, 83, 7D, FC, 00, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + E                                                                                 775B3ABB 2 Bytes  [ 65, A5 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + 12                                                                                775B3ABF 104 Bytes  [ 8B, C6, 5E, C9, C2, 0C, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropStgNameToFmtId + 39                                                                                775B3B46 14 Bytes  [ 0C, 8D, 45, EC, 50, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropStgNameToFmtId + 48                                                                                775B3B55 33 Bytes  [ FF, 15, FC, BA, 5D, 77, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 19                                                                                  775B3B82 39 Bytes  [ 74, 09, FF, 75, FC, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 41                                                                                  775B3BAA 4 Bytes  [ 83, A5, F8, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 46                                                                                  775B3BAF 150 Bytes  [ FF, 00, 53, 8B, 5D, 08, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + DD                                                                                  775B3C46 224 Bytes  JMP 6B53C74D 
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenPropStg + 3D                                                                                    775B3D27 40 Bytes  [ 47, 83, F8, 15, 74, 0F, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenPropStg + 66                                                                                    775B3D50 752 Bytes  [ EB, 31, FF, 75, 18, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 1F5                                                                              775B4041 32 Bytes  [ 50, FF, 75, F8, 56, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 216                                                                              775B4062 2 Bytes  [ FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 219                                                                              775B4065 67 Bytes  [ EC, 51, 51, 8B, 4D, 0C, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 9                                                                                  775B40A9 129 Bytes  [ 48, 0F, 84, 2F, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + F5                                                                                 775B4195 6 Bytes  [ 84, 9F, 00, 00, 00, 48 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + FC                                                                                 775B419C 11 Bytes  [ 6B, 48, 74, 12, 48, 48, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 108                                                                                775B41A8 8 Bytes  [ 48, 74, 34, 48, 0F, 85, CC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 111                                                                                775B41B1 6 Bytes  [ 00, 3B, F7, 0F, 8F, 61 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 9                                                                                    775B42D3 2 Bytes  [ 01, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + C                                                                                    775B42D6 36 Bytes  [ 83, F9, 1E, 0F, 8D, 6A, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 32                                                                                   775B42FC 106 Bytes  [ 00, 49, 0F, 84, 98, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 9D                                                                                   775B4367 36 Bytes  [ 00, 00, 8B, 4D, 08, 89, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + C2                                                                                   775B438C 15 Bytes  [ 00, 00, DF, 6D, F8, 8B, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgPropertyLengthAsVariant + 1F                                                                        775B5DD2 88 Bytes  [ 0F, 8C, 1B, 02, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 40                                                                       775B5E2B 87 Bytes  [ 8A, 45, 20, 88, 45, DB, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 99                                                                       775B5E84 12 Bytes  [ 3B, C1, 0F, 8F, 9E, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + A6                                                                       775B5E91 89 Bytes  [ 00, 83, C1, F6, 3B, C1, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 100                                                                      775B5EEB 55 Bytes  [ 80, 7D, 20, 00, 0F, 85, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 138                                                                      775B5F23 45 Bytes  [ 46, 08, 5F, EB, 64, 8A, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 3A                                                                  775C056E 14 Bytes  [ 0F, 86, 3C, 02, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 49                                                                  775C057D 39 Bytes  [ 00, 8D, 04, 40, 8D, 3C, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 71                                                                  775C05A5 40 Bytes  [ 74, 0E, 8B, 45, 10, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 9A                                                                  775C05CE 26 Bytes  [ 83, 3E, 00, 0F, 8C, 4B, 07, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + B5                                                                  775C05E9 19 Bytes  [ FF, FF, 8B, 45, 14, FF, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 2                                                                775C05FD 15 Bytes  [ 8B, 45, 14, FF, 30, E8, 5F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 12                                                               775C060D 85 Bytes  [ FF, FF, 8B, 0F, 83, F9, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 69                                                               775C0664 1 Byte  [ DC ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 6B                                                               775C0666 32 Bytes  CALL 7750CDAF C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 8C                                                               775C0687 1 Byte  [ 55 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 48                                                                        775C07F0 205 Bytes  [ 8B, CF, 8B, 7D, E4, 8B, D1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 17E                                                                       775C0926 43 Bytes  [ FC, 83, 45, E4, 10, 83, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1AB                                                                       775C0953 43 Bytes  [ 83, 3E, 00, 89, 45, 1C, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1D7                                                                       775C097F 26 Bytes  [ 45, F4, 8B, 40, 04, 83, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1F2                                                                       775C099A 69 Bytes  [ 45, F4, 8B, 40, 04, 03, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF827F3                                                                77A5153D 11 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82802                                                                77A5154C 43 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82831                                                                77A5157B 12 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82841                                                                77A5158B 96 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF828A2                                                                77A515EC 5 Bytes  [ 00, 00, 00, 00, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFlushLruCache + 12                                                                            77A542DD 614 Bytes  [ 43, 72, 79, 70, 74, 45, 6E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + F5                                                                        77A54544 10 Bytes  [ 74, 43, 6F, 6E, 74, 65, 78, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 100                                                                       77A5454F 8 Bytes  [ 79, 70, 74, 49, 6E, 73, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 109                                                                       77A54558 8 Bytes  [ 6C, 4F, 49, 44, 46, 75, 6E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 112                                                                       77A54561 33 Bytes  [ 69, 6F, 6E, 41, 64, 64, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 134                                                                       77A54583 26 Bytes  [ 6C, 6F, 63, 00, 43, 72, 79, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 3A                                                                   77A54CC0 329 Bytes  [ 6E, 63, 6F, 64, 65, 72, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 184                                                                  77A54E0A 54 Bytes  [ 49, 5F, 43, 72, 79, 70, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1BB                                                                  77A54E41 15 Bytes  [ 54, 6C, 73, 00, 49, 5F, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1CB                                                                  77A54E51 35 Bytes  [ 4C, 72, 75, 45, 6E, 74, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1EF                                                                  77A54E75 553 Bytes  [ 49, 5F, 43, 72, 79, 70, 74, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL                                                                                      77A5528D 28 Bytes  [ 90, C2, 00, 00, 59, E9, 9E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 1D                                                                                 77A552AA 50 Bytes  [ 76, 14, 8B, 46, 34, 83, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 50                                                                                 77A552DD 11 Bytes  [ FF, 75, 10, 8B, CE, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 5C                                                                                 77A552E9 14 Bytes  [ FF, F6, 06, 01, 0F, 84, 8E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 6B                                                                                 77A552F8 31 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 21                                                                         77A56BC5 13 Bytes  [ FF, FF, 3B, C6, A3, 20, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 44                                                                         77A56BE8 35 Bytes  JMP 0377A960 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 68                                                                         77A56C0C 197 Bytes  [ 2C, 69, A9, 77, 07, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 12E                                                                        77A56CD2 7 Bytes  [ 00, 00, 29, 6E, A9, 77, 20 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 136                                                                        77A56CDA 169 Bytes  [ 00, 00, 7C, 7B, A9, 77, 21, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet                                                                              77A57A0D 10 Bytes  [ 67, A5, 77, 08, B8, A8, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + B                                                                          77A57A18 11 Bytes  [ 08, B8, A8, 77, 80, 67, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 17                                                                         77A57A24 23 Bytes  [ 10, 46, A5, 77, 3B, B8, A8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 2F                                                                         77A57A3C 23 Bytes  [ 90, 67, A5, 77, 8E, C2, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 47                                                                         77A57A54 76 Bytes  [ 10, 46, A5, 77, F8, B8, A8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + F4                                                                  77A57BB3 113 Bytes  [ 6C, 33, DB, FF, 77, 68, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 166                                                                 77A57C25 148 Bytes  [ D9, 72, 03, 8B, 5D, 14, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 1FB                                                                 77A57CBA 104 Bytes  [ 70, 68, 33, DB, 68, 18, 6D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 265                                                                 77A57D24 58 Bytes  [ 32, 2E, 35, 2E, 32, 39, 2E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 2A0                                                                 77A57D5F 88 Bytes  [ 00, 3B, FB, 0F, 84, 96, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + 5                                                                      77A5833B 40 Bytes  [ FF, D3, 39, 7D, FC, 74, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + 2E                                                                     77A58364 117 Bytes  [ D3, 39, 7D, DC, 74, 05, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + A4                                                                     77A583DA 13 Bytes  [ 00, 85, C0, 0F, 84, 4E, D3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + C4                                                                     77A583FA 28 Bytes  [ 90, 90, 01, 00, 00, 00, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + E1                                                                     77A58417 71 Bytes  [ 00, 41, 30, A9, 77, 05, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + 6                                                                       77A59BDE 144 Bytes  [ A5, 77, FF, 35, 20, 53, AD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + 98                                                                      77A59C70 28 Bytes  [ 85, C0, 74, 1D, 57, 68, A0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + B5                                                                      77A59C8D 301 Bytes  [ 04, 8C, FF, FF, 33, C0, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFreeOIDFunctionAddress + 4B                                                                     77A59DBC 174 Bytes  [ 64, D2, A9, 77, 78, 7E, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProv + 59                                                                      77A59E6B 135 Bytes  [ 00, 89, 31, AA, 77, 18, 6D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 84                                                                     77A59EF4 1 Byte  [ 35 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 86                                                                     77A59EF6 16 Bytes  [ AA, 77, 0B, 00, 00, 00, 35, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 98                                                                     77A59F08 34 Bytes  [ 23, 00, 00, 00, 2F, 6E, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + BC                                                                     77A59F2C 19 Bytes  [ 26, 03, AA, 77, E0, 47, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + D0                                                                     77A59F40 62 Bytes  [ D8, 48, A5, 77, 26, 03, AA, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 6B                                                                                77A5A388 39 Bytes  [ 00, 00, 6A, 02, 56, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 93                                                                                77A5A3B0 130 Bytes  [ D6, 85, C0, 74, 72, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 117                                                                               77A5A434 70 Bytes  [ E0, FF, D6, 39, 5D, E4, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 15E                                                                               77A5A47B 21 Bytes  [ FF, 8B, F0, 85, F6, 0F, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenHKCUKeyExU                                                                                    77A5A494 10 Bytes  [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + 90                                                                                   77A5A550 3 Bytes  [ 32, 00, 5C ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + 94                                                                                   77A5A554 17 Bytes  [ 50, 00, 65, 00, 72, 00, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + A6                                                                                   77A5A566 1 Byte  [ 63 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + A8                                                                                   77A5A568 68 Bytes  [ 65, 00, 00, 00, 68, 80, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + EE                                                                                   77A5A5AE 47 Bytes  [ 90, 90, 90, FF, 25, C0, 11, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 2                                                77A5A78F 136 Bytes  [ FF, 39, 5E, 14, 74, B9, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 8B                                               77A5A818 17 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 9D                                               77A5A82A 73 Bytes  [ 00, 33, C0, 39, 45, 0C, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + E7                                               77A5A874 33 Bytes  [ 00, 8B, 07, 85, C0, 74, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 109                                              77A5A896 37 Bytes  [ FF, D0, 85, C0, 0F, 85, AE, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 1                                                                             77A5AA76 9 Bytes  [ 46, 0C, 85, C0, 0F, 85, E6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + B                                                                             77A5AA80 8 Bytes  [ 3B, 35, 2C, 51, AD, 77, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 14                                                                            77A5AA89 39 Bytes  [ 46, 08, A3, 2C, 51, AD, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 70                                                                            77A5AAE5 33 Bytes  [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 93                                                                            77A5AB08 16 Bytes  [ F6, 47, 2A, 04, FF, 76, 04, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 12                                                                                   77A5B0FE 22 Bytes  [ 37, 00, 38, 00, 39, 00, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 29                                                                                   77A5B115 1 Byte  [ 2D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 2B                                                                                   77A5B117 60 Bytes  [ EB, A9, 6A, 57, FF, 15, 4C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 68                                                                                   77A5B154 30 Bytes  [ 00, 00, 8B, 45, 0C, 3B, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 87                                                                                   77A5B173 42 Bytes  [ 8B, 45, 18, 83, 20, 00, 33, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + D                                                                                   77A5C1AB 86 Bytes  [ 89, 9D, E4, FE, FF, FF, 29, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 64                                                                                  77A5C202 8 Bytes  [ FF, 01, 0F, 85, D7, 71, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 6D                                                                                  77A5C20B 30 Bytes  [ 85, F0, FE, FF, FF, D1, EF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 8C                                                                                  77A5C22A 48 Bytes  CALL ECA5C22D 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 5                                                                          77A5C25B 4 Bytes  [ FE, FF, FF, 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + A                                                                          77A5C260 30 Bytes  [ F8, FE, FF, FF, 68, 04, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 29                                                                         77A5C27F 26 Bytes  [ FF, FF, B5, E0, FE, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 44                                                                         77A5C29A 13 Bytes  [ 74, 12, FF, B5, E0, FE, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 8A                                                                         77A5C2E0 50 Bytes  [ 51, AD, 77, FF, 15, CC, 12, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 25                                                                                   77A5C4DB 79 Bytes  [ 68, 18, B5, A5, 77, 53, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 75                                                                                   77A5C52B 28 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 93                                                                                   77A5C549 2 Bytes  [ CC, 12 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 97                                                                                   77A5C54D 6 Bytes  [ 39, 3D, D4, 50, AD, 77 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 9E                                                                                   77A5C554 23 Bytes  [ 35, BE, 5B, B8, A5, 77, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 4C                                                                               77A5E98A 114 Bytes  [ 76, 67, 8B, 45, 08, 8B, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + BF                                                                               77A5E9FD 46 Bytes  [ 45, 08, 8B, 40, 04, 8B, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + EE                                                                               77A5EA2C 6 Bytes  [ FF, 75, F8, E8, 0C, E7 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 11D                                                                              77A5EA5B 34 Bytes  [ 5D, 0C, 85, DB, 56, 57, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 151                                                                              77A5EA8F 57 Bytes  [ 00, 00, 00, 8B, 47, 14, 50, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 23                                                                        77A5EB5A 61 Bytes  [ 74, 06, 83, 7D, 18, 00, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 61                                                                        77A5EB98 20 Bytes  [ 80, 00, 00, F7, DE, 1B, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 76                                                                        77A5EBAD 72 Bytes  [ 0F, 00, 56, 53, FF, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + BF                                                                        77A5EBF6 43 Bytes  [ 75, 9D, 8D, 45, 0C, 50, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + EB                                                                        77A5EC22 23 Bytes  [ 50, FF, 15, 4C, 12, A5, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 14                                                                                77A5F613 14 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 23                                                                                77A5F622 16 Bytes  [ 00, 00, 58, 49, A5, 77, BC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 34                                                                                77A5F633 25 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 4E                                                                                77A5F64D 6 Bytes  [ 00, 00, 00, 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 55                                                                                77A5F654 30 Bytes  [ 00, 00, 00, 00, 1C, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + C                                                                              77A5F6F4 54 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 43                                                                             77A5F72B 4 Bytes  [ 00, 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 49                                                                             77A5F731 1 Byte  [ 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 4B                                                                             77A5F733 4 Bytes  [ 00, 00, 00, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 50                                                                             77A5F738 2 Bytes  [ 1C, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 17                                                                                77A5FFAC 54 Bytes  [ 55, 8B, EC, 8B, 45, 08, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 4E                                                                                77A5FFE3 15 Bytes  [ 00, 08, 00, 00, 00, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 5F                                                                                77A5FFF4 57 Bytes  [ 04, 00, 00, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 99                                                                                77A6002E 11 Bytes  [ FF, 76, 28, 53, FF, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + A5                                                                                77A6003A 7 Bytes  [ 8B, 46, 28, A9, 00, 00, 04 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 44                                                                             77A602C2 1 Byte  [ 1C ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 47                                                                             77A602C5 1 Byte  [ 18 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 4A                                                                             77A602C8 1 Byte  [ 14 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 8D                                                                             77A6030B 70 Bytes  [ 8B, 45, FC, 89, 06, 33, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + D4                                                                             77A60352 66 Bytes  [ 00, FF, 00, 3D, 00, 00, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + E                                                                                 77A60395 82 Bytes  [ 33, C0, EB, F8, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 61                                                                                77A603E8 1 Byte  [ 36 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 63                                                                                77A603EA 52 Bytes  [ 3D, E4, 12, A5, 77, 68, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 98                                                                                77A6041F 145 Bytes  [ 85, C0, 74, 3A, FF, 75, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + 85                                                                              77A604B1 24 Bytes  [ 76, 08, 53, FF, 75, 14, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + 9E                                                                              77A604CA 43 Bytes  [ 75, 18, 6A, 40, FF, 15, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + CA                                                                              77A604F6 28 Bytes  [ 76, 08, 53, FF, 75, 14, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + E7                                                                              77A60513 72 Bytes  [ 7D, 10, 83, E7, 01, 74, 2D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + 1F                                                                            77A6055C 157 Bytes  [ 4D, FC, 8B, 45, F0, 3B, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + BD                                                                            77A605FA 2 Bytes  [ 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + C0                                                                            77A605FD 155 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 64                                                                 77A60699 150 Bytes  [ FF, 85, C0, 74, 59, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + FB                                                                 77A60730 47 Bytes  [ 00, 08, 00, 74, 6F, 81, FE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 12B                                                                77A60760 13 Bytes  [ 5C, 00, 4D, 00, 69, 00, 63, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 139                                                                77A6076E 147 Bytes  [ 6F, 00, 66, 00, 74, 00, 5C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 1CD                                                                77A60802 1 Byte  [ 63 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 57                                                                                   77A608D6 17 Bytes  CALL 011DAED3 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 69                                                                                   77A608E8 34 Bytes  [ EE, 8E, A6, 77, 6B, 36, A7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 8C                                                                                   77A6090B 21 Bytes  [ 77, 63, FC, A8, 77, C5, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + A2                                                                                   77A60921 5 Bytes  [ 75, 18, FF, 76, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + A8                                                                                   77A60927 55 Bytes  [ 15, A0, 12, A5, 77, 8D, 7C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfo + 2                                                                         77A6098A 75 Bytes  [ 85, C0, 89, 43, 34, 0F, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + 2A                                                                      77A609D6 105 Bytes  [ A8, 77, 9F, 27, A7, 77, 28, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + 94                                                                      77A60A40 62 Bytes  [ 85, C0, 0F, 84, AC, 23, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + D3                                                                      77A60A7F 23 Bytes  [ FF, 85, C0, 0F, 85, 0D, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + EB                                                                      77A60A97 7 Bytes  [ 85, C0, 0F, 85, B8, 38, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + F3                                                                      77A60A9F 17 Bytes  [ 53, 8D, 45, D0, 50, 68, A4, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 6B                                                                       77A60BB0 10 Bytes  [ 8B, 75, 14, 8B, 45, 14, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 77                                                                       77A60BBC 4 Bytes  [ 23, C7, 81, CE ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 7E                                                                       77A60BC3 2 Bytes  [ 80, 3D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 82                                                                       77A60BC7 10 Bytes  [ 08, 00, 8D, 5D, EC, 75, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 8E                                                                       77A60BD3 4 Bytes  [ 01, 83, 7D, DC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + E                                                                            77A60D7F 132 Bytes  [ 85, C0, 0F, 84, D9, 02, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + 93                                                                           77A60E04 44 Bytes  [ FF, 55, 8B, EC, 51, 51, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + C0                                                                           77A60E31 8 Bytes  [ FF, 83, FA, 12, 0F, 87, 67, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + C9                                                                           77A60E3A 32 Bytes  [ FF, FF, 24, 95, B2, FD, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + EA                                                                           77A60E5B 18 Bytes  CALL 512B1D63 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + B                                                                       77A60FCD 24 Bytes  [ EB, F5, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 24                                                                      77A60FE6 10 Bytes  [ 45, FC, 50, 6A, 01, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 2F                                                                      77A60FF1 21 Bytes  [ 04, 00, 00, 00, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 45                                                                      77A61007 7 Bytes  [ 14, 8B, 4D, E8, 89, 08, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 4D                                                                      77A6100F 1 Byte  [ 10 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + D                                                                          77A61250 7 Bytes  [ 50, AD, 77, 0D, 04, 80, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 15                                                                         77A61258 15 Bytes  [ 50, FF, 75, 14, FF, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 25                                                                         77A61268 32 Bytes  [ 00, 00, 85, C0, 0F, 84, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 46                                                                         77A61289 78 Bytes  [ FF, 33, DB, 89, 5D, DC, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 95                                                                         77A612D8 36 Bytes  [ 39, 5D, DC, 74, 09, 53, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 3D                                                                                  77A61480 7 Bytes  [ 5F, 5E, 5B, 5D, C2, 04, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 49                                                                                  77A6148C 32 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 6A                                                                                  77A614AD 43 Bytes  [ 55, 8B, EC, FF, 75, 0C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 96                                                                                  77A614D9 49 Bytes  [ 89, 50, 10, 8B, 11, 85, D2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + CA                                                                                  77A6150D 19 Bytes  [ 8B, FF, 55, 8B, EC, 8B, 55, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 6C                                                                               77A62AFA 27 Bytes  CALL 47681632 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 88                                                                               77A62B16 83 Bytes  [ 24, 78, 33, F5, D1, C6, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + DC                                                                               77A62B6A 26 Bytes  JMP 66DA15A2 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + F7                                                                               77A62B85 63 Bytes  [ AC, 24, 80, 00, 00, 00, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 137                                                                              77A62BC5 31 Bytes  [ 00, 33, F5, D1, C6, 89, B4, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareIntegerBlob + 6                                                                           77A62D9B 16 Bytes  JMP EF23F28B 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareIntegerBlob + 17                                                                          77A62DAC 120 Bytes  [ 74, 24, 70, 8B, 6C, 24, 78, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + B                                                                           77A62E25 70 Bytes  JMP 69CA1F35 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 52                                                                          77A62E6C 110 Bytes  [ F0, 23, EB, 0B, F3, 23, F1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + C1                                                                          77A62EDB 79 Bytes  [ AC, 24, B4, 00, 00, 00, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 111                                                                         77A62F2B 11 Bytes  [ 33, F5, D1, C6, 89, B4, 24, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 11D                                                                         77A62F37 55 Bytes  [ EB, C1, C5, 05, 8D, 84, 28, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCRLContextProperty + 11                                                                       77A6363C 75 Bytes  [ 8B, AC, 24, F4, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 27                                                                      77A63688 42 Bytes  [ F5, 8B, AC, 24, 10, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 52                                                                      77A636B3 46 Bytes  CALL 60DA21EB 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 81                                                                      77A636E2 46 Bytes  JMP 8D05C5C1 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + B0                                                                      77A63711 27 Bytes  [ 33, F5, 8B, AC, 24, 2C, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + CC                                                                      77A6372D 10 Bytes  JMP E833EF33 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 5B                                                                           77A6390C 37 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 81                                                                           77A63932 88 Bytes  [ FB, 08, 57, 89, 45, B0, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + DA                                                                           77A6398B 15 Bytes  [ FF, 8B, 55, B0, 6A, 05, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + EA                                                                           77A6399B 33 Bytes  [ 33, C0, B9, 10, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 10C                                                                          77A639BD 221 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 15                                                                                 77A640BA 53 Bytes  [ 8D, 45, FC, 50, FF, 75, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 4B                                                                                 77A640F0 34 Bytes  [ 50, 6A, 00, FF, 75, F8, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 6E                                                                                 77A64113 102 Bytes  [ C0, 0F, 84, C3, D1, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + D5                                                                                 77A6417A 87 Bytes  [ 85, C0, 74, 2D, 83, C6, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 12D                                                                                77A641D2 19 Bytes  [ FF, 8D, 46, 54, 50, E8, 1B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 38                                                                      77A64FB0 7 Bytes  [ 74, 20, 8B, 5F, 14, 53, E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 40                                                                      77A64FB8 42 Bytes  [ 81, FF, FF, 56, 57, E8, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 6C                                                                      77A64FE4 24 Bytes  [ 6A, 00, FF, 75, 08, E8, 99, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 85                                                                      77A64FFD 22 Bytes  [ 0F, 85, 99, 47, 01, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 9C                                                                      77A65014 49 Bytes  [ 85, C0, 0F, 84, EE, 47, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 6                                                                           77A65384 1 Byte  [ 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 8                                                                           77A65386 3 Bytes  [ C7, 45, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + D                                                                           77A6538B 260 Bytes  [ 00, 00, 8B, 55, FC, F6, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 112                                                                         77A65490 116 Bytes  [ 69, 10, 33, C7, 03, DD, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 187                                                                         77A65505 43 Bytes  [ C6, 03, DA, 33, C2, 23, C3, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 1                                                                            77A656C3 31 Bytes  [ C7, C1, C6, 0E, 8B, 69, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 21                                                                           77A656E3 153 Bytes  [ 69, 34, 33, C2, 23, C7, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + BB                                                                           77A6577D 318 Bytes  [ 22, 61, 9D, 6D, 33, C2, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 1FA                                                                          77A658BC 284 Bytes  [ 17, 8B, C7, 83, F0, FF, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 317                                                                          77A659D9 135 Bytes  [ C6, 0F, 8B, C3, 83, F0, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 1A                                                                            77A65EFC 97 Bytes  [ 33, C0, F3, A6, 8B, 75, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 7C                                                                            77A65F5E 14 Bytes  [ 58, 18, 8D, 50, 08, EB, E3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 8B                                                                            77A65F6D 65 Bytes  [ 97, 83, C0, D0, EB, 35, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 154                                                                           77A66036 51 Bytes  [ 00, EB, ED, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 1E0                                                                           77A660C2 84 Bytes  [ 5F, 5E, 5B, 5D, C2, 04, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 4B                                                                          77A66552 2 Bytes  [ 4D, 14 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 4E                                                                          77A66555 8 Bytes  [ 55, 10, 8B, 75, 0C, 89, 59, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 57                                                                          77A6655E 22 Bytes  [ 01, 89, 51, 08, 8B, C8, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 6E                                                                          77A66575 73 Bytes  [ 75, 10, 85, F6, 75, 93, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + 32                                                                          77A665C9 49 Bytes  [ C2, 20, 00, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + A1                                                                          77A66638 28 Bytes  [ 7C, 0D, F7, 45, 0C, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + C0                                                                          77A66657 1 Byte  [ 14 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + C2                                                                          77A66659 38 Bytes  [ 8D, 47, 20, 89, 45, 14, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + E9                                                                          77A66680 67 Bytes  [ 85, C0, 0F, 85, D3, 9A, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 32                                                               77A66FE6 109 Bytes  CALL F5306C76 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + A0                                                               77A67054 16 Bytes  [ 18, 04, 0F, 85, 33, 5A, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + B1                                                               77A67065 7 Bytes  [ 18, FF, 75, 14, FF, 75, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + BA                                                               77A6706E 4 Bytes  [ 0C, FF, 75, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + BF                                                               77A67073 122 Bytes  [ 55, E0, 8B, F8, 53, FF, 75, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 36                                                                           77A672F2 81 Bytes  [ 00, 85, C0, 74, 1E, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 88                                                                           77A67344 3 Bytes  [ 45, 10, 89 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 8C                                                                           77A67348 37 Bytes  [ 83, C0, 04, 50, FF, 15, BC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + B2                                                                           77A6736E 81 Bytes  [ 20, 89, 56, 24, 89, 56, 28, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntry + 35                                                                             77A673C0 218 Bytes  [ 8B, 45, 1C, C7, 00, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + CB                                                                   77A6749B 25 Bytes  [ 00, 00, 8B, 46, 0C, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + E5                                                                   77A674B5 2 Bytes  [ 58, 0C ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + E8                                                                   77A674B8 59 Bytes  [ 47, 10, 89, 45, F8, 8B, 47, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 125                                                                  77A674F5 7 Bytes  [ EB, E4, 8B, 45, 18, 83, 20 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 156                                                                  77A67526 73 Bytes  [ 8D, 47, 20, 50, 53, FF, D6, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 50                                                                             77A6779C 99 Bytes  [ 85, C0, 89, 45, C8, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + B5                                                                             77A67801 2 Bytes  [ 11, 86 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + BA                                                                             77A67806 89 Bytes  [ 43, 04, 8B, 40, 40, 0B, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 114                                                                            77A67860 58 Bytes  [ 45, A0, 83, C0, 04, 50, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 14F                                                                            77A6789B 42 Bytes  [ FF, 89, 38, 8B, 45, A0, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCRLInStore + 2E                                                                              77A6797D 2 Bytes  [ 3B, 86 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCRLInStore + 32                                                                              77A67981 138 Bytes  [ 8D, 5F, 1C, 83, 79, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 1D                                                                       77A67A0C 7 Bytes  [ 00, 89, 45, C4, E8, 88, D1 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 25                                                                       77A67A14 4 Bytes  [ FF, 89, 45, C8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 2A                                                                       77A67A19 53 Bytes  [ 43, 38, 89, 45, CC, 8B, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 60                                                                       77A67A4F 18 Bytes  [ 55, 08, 0F, 88, DC, 7E, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 73                                                                       77A67A62 44 Bytes  [ 39, 56, 34, BB, 00, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + AC                                                               77A67CE9 3 Bytes  [ F7, 86, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + B0                                                               77A67CED 264 Bytes  [ 8B, 46, 10, 6A, 05, 59, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 1B9                                                              77A67DF6 100 Bytes  [ 33, C0, 40, 5F, 5E, 5B, C9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 21E                                                              77A67E5B 1 Byte  [ 5D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 220                                                              77A67E5D 24 Bytes  [ 8B, 43, 04, 8B, 0C, 85, 40, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 13                                                                        77A67F03 24 Bytes  [ 5D, FF, FF, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 2C                                                                        77A67F1C 34 Bytes  [ 56, 8B, 75, 08, 57, 33, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 4F                                                                        77A67F3F 13 Bytes  [ 70, 6C, FF, 70, 68, 68, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 5D                                                                        77A67F4D 64 Bytes  [ FF, 3B, C7, 74, 1D, 6A, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 9F                                                                        77A67F8F 3 Bytes  [ 12, 2C, 00 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 27                                                                                   77A688E1 32 Bytes  [ 55, 8B, EC, F6, 45, 14, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 48                                                                                   77A68902 85 Bytes  [ 85, C0, 0F, 85, 7C, 15, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 9E                                                                                   77A68958 78 Bytes  [ 45, 0C, 89, 45, F0, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + ED                                                                                   77A689A7 80 Bytes  [ 55, 8B, EC, 8B, 48, 08, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 13E                                                                                  77A689F8 92 Bytes  [ 7D, 08, 83, 7F, 18, 00, 6A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + A3                                                                        77A693C1 9 Bytes  [ 5B, 5F, C9, C2, 10, 00, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + DD                                                                        77A693FB 17 Bytes  [ 4D, 0C, 8B, 11, 8B, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + EF                                                                        77A6940D 25 Bytes  [ 09, 50, 04, F6, 41, 05, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + 109                                                                       77A69427 25 Bytes  [ 5D, C2, 08, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + 123                                                                       77A69441 3 Bytes  [ 5E, 5D, C2 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + 56                                                                        77A698B5 22 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + 6D                                                                        77A698CC 85 Bytes  [ 8D, 46, 1C, 50, FF, 15, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + C4                                                                        77A69923 4 Bytes  [ 00, 8B, 46, 48 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + C9                                                                        77A69928 16 Bytes  [ 48, 0C, 85, C9, 74, 07, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + DA                                                                        77A69939 33 Bytes  [ 48, 10, 85, C9, 74, 07, 6A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCertificateChainPolicy + 34                                                                77A69A80 30 Bytes  [ 9A, 64, 01, 00, 8B, 45, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCertificateChainPolicy + 53                                                                77A69A9F 180 Bytes  [ 70, 28, 83, C0, 2C, 51, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + 92                                                                             77A69B54 34 Bytes  [ 0F, 85, 59, 63, 01, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + B5                                                                             77A69B77 45 Bytes  [ 5F, 1C, 53, 6A, 00, FF, 76, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + E3                                                                             77A69BA5 27 Bytes  [ FA, FF, FF, 85, C0, 74, 72, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + FF                                                                             77A69BC1 19 Bytes  [ 00, 85, C0, 74, 58, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + 113                                                                            77A69BD5 38 Bytes  [ FF, 8B, 3F, 85, FF, 74, 13, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetSubjectCertificateFromStore + 84                                                              77A6A0BD 84 Bytes  [ 0F, 86, D1, 00, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 21                                                                             77A6A112 9 Bytes  [ FF, 85, C0, 0F, 84, A3, F3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 2B                                                                             77A6A11C 113 Bytes  [ 75, F8, 8B, 4D, F0, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 9D                                                                             77A6A18E 43 Bytes  [ FF, BB, 00, 00, 01, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + C9                                                                             77A6A1BA 23 Bytes  [ 02, 0B, F2, 8B, 47, 10, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + E1                                                                             77A6A1D2 40 Bytes  [ 06, 81, CE, 80, 00, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 1                                                                         77A6A8E5 8 Bytes  [ 45, F4, 5F, 5E, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + A                                                                         77A6A8EE 8 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 13                                                                        77A6A8F7 31 Bytes  [ EC, 8D, 45, 10, 50, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 33                                                                        77A6A917 3 Bytes  [ 63, 69, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 3B                                                                        77A6A91F 2 Bytes  [ D9, 01 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 6E                                                                                77A6B018 18 Bytes  [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + BB                                                                                77A6B065 47 Bytes  [ 0B, 00, 89, 45, FC, E8, 36, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + EB                                                                                77A6B095 46 Bytes  [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 11A                                                                               77A6B0C4 27 Bytes  [ 70, 68, 68, E0, 45, A5, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 137                                                                               77A6B0E1 110 Bytes  [ 0F, 84, 59, FD, FE, FF, E9, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + 12                                                                         77A6B7DA 135 Bytes  [ 33, C0, 8B, FE, AA, 8D, 46, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + 9A                                                                         77A6B862 7 Bytes  [ EB, F5, 90, 90, 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + A2                                                                         77A6B86A 8 Bytes  [ FF, 55, 8B, EC, 51, 83, 65, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + AB                                                                         77A6B873 81 Bytes  [ 53, 56, 8B, 75, 08, 57, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + FD                                                                         77A6B8C5 19 Bytes  [ 47, 08, 33, C0, 40, 5F, 5E, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 6                                                                                77A6C113 65 Bytes  [ EF, 11, 81, 7D, 08, B8, 67, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 48                                                                               77A6C155 28 Bytes  [ 30, 57, 33, FF, 83, FE, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 65                                                                               77A6C172 1 Byte  [ FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 67                                                                               77A6C174 9 Bytes  [ 34, 8B, 75, 0C, 89, 0E, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 71                                                                               77A6C17E 2 Bytes  [ 70, 04 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 55                                                                                 77A6C50F 3 Bytes  [ 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 59                                                                                 77A6C513 18 Bytes  [ FF, 55, 8B, EC, 83, EC, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 6C                                                                                 77A6C526 2 Bytes  [ 7D, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + DF                                                                                 77A6C599 60 Bytes  [ F0, 3B, F7, 0F, 84, 78, 1E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 11C                                                                                77A6C5D6 38 Bytes  [ 4D, 10, 29, 31, 5E, 5D, C2, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 1                                                                            77A6D323 6 Bytes  [ CF, 8B, D1, C1, E9, 02 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 8                                                                            77A6D32A 96 Bytes  [ F8, F3, A5, 8B, CA, 83, E1, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + F2                                                                           77A6D414 369 Bytes  [ 47, 14, 89, 43, 70, E9, DC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 2BF                                                                          77A6D5E1 126 Bytes  [ 8D, 4D, CC, 51, 68, 98, 69, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 33E                                                                          77A6D660 13 Bytes  [ 85, C0, 74, 78, 8B, 4D, F4, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + E                                                                                   77A6D879 13 Bytes  [ FF, 4B, 83, C6, 08, EB, CB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + 1C                                                                                  77A6D887 177 Bytes  [ 55, 8B, EC, 83, EC, 18, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + CE                                                                                  77A6D939 3 Bytes  [ 84, BA, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + D3                                                                                  77A6D93E 5 Bytes  [ 48, 0F, 85, 92, 02 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + DA                                                                                  77A6D945 18 Bytes  [ 8B, 46, 48, 3B, C2, 0F, 84, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 14                                                                            77A6DE27 116 Bytes  [ 00, 8B, 76, 38, 83, C6, 58, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 89                                                                            77A6DE9C 10 Bytes  [ 89, B5, 60, FF, FF, FF, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 94                                                                            77A6DEA7 5 Bytes  [ 00, 00, E9, 92, E1 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + F4                                                                            77A6DF07 34 Bytes  [ 9C, 53, FF, 75, 14, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 118                                                                           77A6DF2B 57 Bytes  [ 89, B5, 68, FF, FF, FF, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 38                                                         77A6DF6F 17 Bytes  [ 85, 78, FF, FF, FF, 3B, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 4A                                                         77A6DF81 5 Bytes  [ 70, 0C, E8, 19, F0 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 50                                                         77A6DF87 27 Bytes  [ FF, 89, 45, E4, 85, C0, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 6C                                                         77A6DFA3 6 Bytes  [ 89, 55, E4, E9, CC, E0 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 73                                                         77A6DFAA 52 Bytes  [ FF, 48, 75, 15, 8B, B6, 08, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + F                                                                                     77A6EB1D 79 Bytes  [ EC, 83, EC, 18, 53, 56, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 5F                                                                                    77A6EB6D 5 Bytes  [ A1, 00, 00, 00, 85 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 65                                                                                    77A6EB73 23 Bytes  [ 0F, 84, 89, 00, 00, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 7D                                                                                    77A6EB8B 55 Bytes  [ 85, C0, 74, 73, 6A, 18, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + F                                                                       77A6EBC3 2 Bytes  [ 5B, 04 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 12                                                                      77A6EBC6 69 Bytes  [ DB, 75, 24, 33, F6, 46, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 58                                                                      77A6EC0C 7 Bytes  [ 00, 90, 90, 90, 90, 90, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 60                                                                      77A6EC14 8 Bytes  [ 55, 8B, EC, 51, 51, 53, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 69                                                                      77A6EC1D 219 Bytes  [ 35, 54, 50, AD, 77, 33, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 1                                                                             77A6ED77 23 Bytes  [ 46, 04, 85, C0, 74, 0A, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 1B                                                                            77A6ED91 22 Bytes  [ 8B, FF, 55, 8B, EC, 5D, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 32                                                                            77A6EDA8 51 Bytes  [ 75, 08, FF, 36, FF, 76, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 66                                                                            77A6EDDC 6 Bytes  [ F6, 0F, 84, 83, F1, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 9F                                                                            77A6EE15 19 Bytes  [ 55, 8B, EC, 51, 83, 65, FC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + 2                                                                                    77A6F017 8 Bytes  [ FF, 85, C0, 0F, 84, 3D, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + B                                                                                    77A6F020 139 Bytes  [ 8B, 45, FC, F6, 00, 80, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + 97                                                                                   77A6F0AC 9 Bytes  [ 4D, E4, 3B, 4D, D8, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + A1                                                                                   77A6F0B6 28 Bytes  CALL AB7B6646 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + BE                                                                                   77A6F0D3 45 Bytes  [ 75, 08, FF, 75, 0C, E8, 0F, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 31                                                                     77A6FC50 95 Bytes  [ B3, FE, FF, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 91                                                                     77A6FCB0 56 Bytes  [ C6, 45, F7, C0, C6, 45, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 103                                                                    77A6FD22 13 Bytes  [ FF, 15, 08, 12, A5, 77, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 111                                                                    77A6FD30 11 Bytes  [ FF, 56, FF, 15, 4C, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 11D                                                                    77A6FD3C 15 Bytes  [ FF, FF, 75, 10, FF, 75, 0C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 31                                                                77A707AD 18 Bytes  [ 83, C6, 04, 56, 68, 01, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 44                                                                77A707C0 6 Bytes  [ 83, C6, 04, 56, 68, 02 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 4B                                                                77A707C7 5 Bytes  [ 00, 80, E9, D0, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 52                                                                77A707CE 37 Bytes  [ 66, C7, 06, 04, 00, 83, C6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 78                                                                77A707F4 197 Bytes  [ 80, EB, E5, 66, C7, 06, 08, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 77                                                                             77A70C9F 212 Bytes  [ 90, 90, 90, 90, 90, A1, 7C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 14C                                                                            77A70D74 44 Bytes  [ 75, 0C, FF, D7, 83, 7D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 179                                                                            77A70DA1 34 Bytes  [ 75, 0C, FF, D7, 83, 7D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 19C                                                                            77A70DC4 35 Bytes  [ 75, 0C, FF, D7, 8B, 35, 5C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 1C0                                                                            77A70DE8 27 Bytes  [ 15, 6C, 14, A5, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveStoreFromCollection + 10                                                                   77A70E04 18 Bytes  [ 75, F4, FF, 75, F8, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveStoreFromCollection + 23                                                                   77A70E17 42 Bytes  [ 0C, FF, 75, 08, FF, D6, F7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertUpdateStore                                                                                    77A70E44 142 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertUpdateStore + B5                                                                               77A70EF9 80 Bytes  [ FF, 5F, 5E, 5D, C2, 20, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 22                                                                           77A70F4A 21 Bytes  [ 8D, 45, FC, 50, 8D, 45, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 38                                                                           77A70F60 73 Bytes  [ F6, 06, 20, 74, 1A, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 82                                                                           77A70FAA 138 Bytes  [ 0A, 5B, C9, C2, 14, 00, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 98                                                                                77A71088 49 Bytes  [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + CA                                                                                77A710BA 28 Bytes  [ 01, 00, FF, 75, 08, E8, B4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + E7                                                                                77A710D7 27 Bytes  [ 89, 01, 47, 39, 5D, E0, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 103                                                                               77A710F3 10 Bytes  [ 55, 8B, EC, 6A, 00, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 10F                                                                               77A710FF 98 Bytes  [ 00, 5D, C2, 04, 00, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 21                                                                        77A712AB 37 Bytes  [ 0F, 84, B3, C7, 00, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 47                                                                        77A712D1 18 Bytes  [ C2, 08, 00, 83, 66, 04, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 76                                                                        77A71300 11 Bytes  [ FF, 81, 7D, 08, FF, FF, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 82                                                                        77A7130C 20 Bytes  [ 08, 68, B8, 45, A5, 77, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 97                                                                        77A71321 22 Bytes  [ FF, 75, 18, C7, 45, FC, 01, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 2                                                                                  77A72097 98 Bytes  [ 75, 14, FF, 75, 10, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 6F                                                                                 77A72104 2 Bytes  [ 64, C9 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 73                                                                                 77A72108 2 Bytes  [ 77, C9 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 77                                                                                 77A7210C 105 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + E1                                                                                 77A72176 4 Bytes  [ 45, 2C, 3B, C7 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc                                                                                        77A72424 19 Bytes  [ 43, 72, 79, 70, 74, 44, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + 88                                                                                   77A724AC 111 Bytes  [ C6, 45, F9, 05, 88, 5D, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + F9                                                                                   77A7251D 5 Bytes  [ 01, 8D, 45, EC, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + FF                                                                                   77A72523 39 Bytes  [ D6, 85, C0, 74, 0D, C7, 05, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + 127                                                                                  77A7254B 61 Bytes  [ FF, 55, 8B, EC, 56, 8B, F0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 120                                                                   77A729FF 9 Bytes  [ FF, 85, C0, 74, 1F, FF, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 12A                                                                   77A72A09 2 Bytes  [ 75, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 131                                                                   77A72A10 1 Byte  [ 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 133                                                                   77A72A12 122 Bytes  [ 15, 5C, 14, A5, 77, F7, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 1AE                                                                   77A72A8D 30 Bytes  [ 55, 18, 57, 6A, 05, 59, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + 99                                                                                  77A73033 8 Bytes  [ 00, 63, 00, 72, 00, 6F, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + A2                                                                                  77A7303C 19 Bytes  [ 6F, 00, 66, 00, 74, 00, 5C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + B6                                                                                  77A73050 22 Bytes  [ 43, 00, 65, 00, 72, 00, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + CD                                                                                  77A73067 44 Bytes  [ 00, 5C, 00, 4D, 00, 79, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + FA                                                                                  77A73094 27 Bytes  [ 90, 8B, FF, 55, 8B, EC, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + A                                                                            77A7320F 6 Bytes  [ 85, C0, 0F, 85, 21, 80 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 11                                                                           77A73216 15 Bytes  [ 00, C3, 33, DB, 43, E9, AF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 22                                                                           77A73227 7 Bytes  [ 80, 4D, E5, 04, E9, 9A, BA ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 2B                                                                           77A73230 19 Bytes  [ C7, 06, 03, 00, 00, 00, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 3F                                                                           77A73244 17 Bytes  [ 15, 08, 12, A5, 77, E9, 87, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 27                                                                                77A73EE1 34 Bytes  [ C6, 5E, 5D, C2, 18, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 4A                                                                                77A73F04 3 Bytes  [ 87, 33, 74 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 4F                                                                                77A73F09 93 Bytes  [ 56, FF, 75, 0C, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + AD                                                                                77A73F67 62 Bytes  [ 00, FF, 75, 18, FF, 75, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + EC                                                                                77A73FA6 66 Bytes  [ 0F, 84, 10, 50, 00, 00, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + E                                                                               77A740AF 199 Bytes  [ 90, 45, 6E, 74, 65, 72, 43, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + D9                                                                              77A7417A 5 Bytes  [ C0, 74, 5A, B8, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + DF                                                                              77A74180 44 Bytes  [ 05, 00, 39, 45, FC, 77, 0B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + 10C                                                                             77A741AD 54 Bytes  [ 15, 04, 12, A5, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + 144                                                                             77A741E5 10 Bytes  [ 90, 90, 90, 75, 00, 73, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 23                                                                             77A74523 27 Bytes  [ 8D, 8D, AC, FD, FF, FF, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 3F                                                                             77A7453F 9 Bytes  [ F7, 85, AC, FD, FF, FF, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 49                                                                             77A74549 105 Bytes  [ 0F, 84, 4A, 7C, 00, 00, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemFree + 2                                                                                     77A745B3 14 Bytes  [ C9, C2, 14, 00, 85, DB, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUninstallAsn1Module                                                                           77A745C2 75 Bytes  [ 90, 90, 2A, 00, 00, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 35                                                                                  77A7460F 5 Bytes  [ 90, 90, 90, 90, 90 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 91                                                                                  77A7466B 12 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 9E                                                                                  77A74678 69 Bytes  [ 56, 8B, 75, 08, F6, 46, 2A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + E7                                                                                  77A746C1 29 Bytes  [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 105                                                                                 77A746DF 37 Bytes  [ 00, BB, 00, 00, 00, 80, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CloseCertPerformanceData + 3A                                                                        77A81CFE 84 Bytes  [ 25, CC, 11, A5, 77, FF, 40, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 4                                                                                      77A81D53 18 Bytes  [ 18, 0F, B7, D2, C1, E3, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 17                                                                                     77A81D66 3 Bytes  [ CA, AA, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 1B                                                                                     77A81D6A 6 Bytes  [ 33, C0, E9, 66, 93, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 22                                                                                     77A81D71 148 Bytes  [ 90, 90, 90, 63, 72, 79, 70, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + B7                                                                                     77A81E06 66 Bytes  [ 00, 00, 2D, 2D, 2D, 2D, 2D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 2F                                                                            77A8242C 33 Bytes  [ 61, 00, 6C, 00, 43, 00, 6F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 51                                                                            77A8244E 77 Bytes  [ 6F, 00, 6E, 00, 00, 00, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 9F                                                                            77A8249C 46 Bytes  [ 54, 00, 69, 00, 74, 00, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 2B                                                                                  77A824CC 1 Byte  [ 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 2D                                                                                  77A824CE 25 Bytes  [ 6D, 00, 61, 00, 69, 00, 6C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 47                                                                                  77A824E8 79 Bytes  [ 4C, 00, 00, 00, 43, 00, 4E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 97                                                                                  77A82538 70 Bytes  [ 48, 00, 41, 00, 31, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + 43                                                                           77A82580 39 Bytes  [ 31, 2E, 33, 2E, 31, 34, 2E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + 6B                                                                           77A825A8 69 Bytes  [ 53, 00, 41, 00, 00, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + B3                                                                           77A825F0 30 Bytes  [ 31, 2E, 33, 2E, 31, 34, 2E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 1F                                                                               77A82610 59 Bytes  [ 73, 00, 68, 00, 61, 00, 52, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 5B                                                                               77A8264C 1 Byte  [ 53 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 5D                                                                               77A8264E 106 Bytes  [ 41, 00, 00, 00, 90, 90, 31, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + C8                                                                               77A826B9 78 Bytes  [ 00, 53, 00, 44, 00, 48, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 117                                                                              77A82708 1 Byte  [ 53 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumProvidersU + 83                                                                             77A82884 279 Bytes  [ 6F, 73, 73, 53, 65, 74, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 1E                                                                                 77A8299C 170 Bytes  [ 31, 2E, 32, 2E, 38, 34, 30, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + C9                                                                                 77A82A47 100 Bytes  [ 00, 06, 00, 00, 00, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 12F                                                                                77A82AAD 29 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 14D                                                                                77A82ACB 41 Bytes  [ 55, 8B, EC, 8B, 0D, 24, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 177                                                                                77A82AF5 35 Bytes  [ EB, 2E, A1, 44, 73, AD, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 7C                                                                            77A83565 34 Bytes  [ 08, FF, 15, E4, 52, AD, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 9F                                                                            77A83588 17 Bytes  [ EC, 81, EC, 0C, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + B1                                                                            77A8359A 3 Bytes  [ 08, 8D, 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + B5                                                                            77A8359E 83 Bytes  [ FE, FF, FF, 51, 50, 68, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 163                                                                           77A8364C 14 Bytes  [ 02, 00, 56, 57, 68, 98, 27, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 12                                                                            77A83819 2 Bytes  [ FF, E0 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 15                                                                            77A8381C 3 Bytes  JMP 77A83611 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 19                                                                            77A83820 135 Bytes  [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + A1                                                                            77A838A8 111 Bytes  [ 8D, DC, FD, FF, FF, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 111                                                                           77A83918 3 Bytes  [ B5, DC, FD ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + A8                                                                            77A83A9B 4 Bytes  [ FF, 8B, CB, 51 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + AE                                                                            77A83AA1 21 Bytes  [ 0C, 89, 45, FC, 8B, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + C4                                                                            77A83AB7 3 Bytes  [ A5, 77, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + C8                                                                            77A83ABB 17 Bytes  [ 85, C8, FD, FF, FF, 89, B5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + DA                                                                            77A83ACD 25 Bytes  [ D7, 85, C0, 74, 09, 83, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 2                                                                             77A83AE7 12 Bytes  [ FF, FF, 85, F0, FD, FF, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + F                                                                             77A83AF4 53 Bytes  [ 77, 08, 39, B5, F0, FD, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 45                                                                            77A83B2A 39 Bytes  [ 15, 5C, 12, A5, 77, 6A, 0E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 6D                                                                            77A83B52 30 Bytes  [ 53, FF, 75, 0C, FF, B5, C8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 8C                                                                            77A83B71 22 Bytes  [ FF, 75, 34, 8B, BD, CC, FD, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4                                                                       77A86C12 70 Bytes  [ 45, 18, 68, 15, 00, 09, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4B                                                                      77A86C59 2 Bytes  [ FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4E                                                                      77A86C5C 167 Bytes  [ EC, 8B, 45, 10, 8B, 00, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + F6                                                                      77A86D04 50 Bytes  [ FF, 1F, 00, 00, FD, 3F, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 2E                                                                      77A86D37 257 Bytes  [ EB, 1E, 33, C0, 85, D2, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 131                                                                     77A86E3A 10 Bytes  [ 40, EB, 22, 6A, 0D, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 13C                                                                     77A86E45 37 Bytes  [ 8B, 45, 0C, 83, 20, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 162                                                                     77A86E6B 42 Bytes  [ 00, 58, 0E, A8, 77, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 18D                                                                     77A86E96 108 Bytes  [ FF, 55, 8B, EC, 81, EC, 88, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + B                                                                     77A86FFE 8 Bytes  [ 18, 68, E0, 61, A8, 77, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + 14                                                                    77A87007 100 Bytes  [ 15, E4, 12, A5, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + 7A                                                                    77A8706D 113 Bytes  [ 8B, 4D, D0, 89, 08, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + EC                                                                    77A870DF 5 Bytes  [ F4, E8, 48, 72, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + F2                                                                    77A870E5 76 Bytes  [ 85, C0, 7E, 29, 8B, 45, B8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 6C                                                                            77A872DA 43 Bytes  [ DC, 03, D8, 89, 5D, C4, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 98                                                                            77A87306 2 Bytes  [ EC, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 9B                                                                            77A87309 1 Byte  [ 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 9D                                                                            77A8730B 294 Bytes  [ 89, 45, C0, 33, C0, 40, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 9C                                                                            77A87433 43 Bytes  [ 50, 8D, 45, CC, 50, 56, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + C8                                                                            77A8745F 63 Bytes  [ 45, CC, 2B, F0, 89, 75, 88, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 108                                                                           77A8749F 63 Bytes  JMP 77A87693 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 148                                                                           77A874DF 40 Bytes  [ 66, A8, 77, 8D, 45, DC, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 171                                                                           77A87508 41 Bytes  [ 4D, E0, 85, C0, 0F, 84, FE, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 13                                              77A87856 17 Bytes  [ D8, 89, 5D, AC, 85, DB, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 25                                              77A87868 35 Bytes  [ FF, 47, 89, 3B, C7, 43, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 49                                              77A8788C 43 Bytes  [ B5, 70, FF, FF, FF, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 75                                              77A878B8 39 Bytes  [ 4B, 50, 89, 4D, CC, 89, 79, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 9D                                              77A878E0 109 Bytes  [ 50, FF, 75, D4, FF, 75, 98, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDeleteCRLFromStore + 2                                                                           77A88142 221 Bytes  [ 15, 4C, 12, A5, 77, 83, 7D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 7D                                                                              77A88231 31 Bytes  [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 9D                                                                              77A88251 35 Bytes  CALL 77A8816D C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + C1                                                                              77A88275 41 Bytes  [ 7D, 0C, 0E, 56, 57, 0F, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + EC                                                                              77A882A0 26 Bytes  [ 83, 3F, 03, 75, 78, 57, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 107                                                                             77A882BB 24 Bytes  [ 15, BC, 12, A5, 77, 57, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + E                                                                                77A88487 23 Bytes  [ 8B, F0, 85, F6, 74, 2D, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 26                                                                               77A8849F 112 Bytes  [ C0, 04, 49, 75, F5, 68, 4B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 97                                                                               77A88510 6 Bytes  [ 5D, 0C, 56, 8B, 75, 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 9E                                                                               77A88517 73 Bytes  [ 46, 0C, 57, 33, FF, F6, C3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + E8                                                                               77A88561 198 Bytes  [ 70, 0C, 6A, 24, FF, 36, E8, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSaveStore + 2B                                                                                   77A88969 180 Bytes  [ 8B, 45, A8, 83, 38, 14, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToStore + 4                                                                 77A88A1E 55 Bytes  [ C8, 83, E1, 03, F3, A4, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToStore + 3C                                                                77A88A56 62 Bytes  [ 7D, B4, 00, 0F, 85, A6, 01, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddCRLContextToStore + 6                                                                         77A88A95 8 Bytes  [ 50, 57, 56, 89, 45, BC, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddCRLContextToStore + 2A                                                                        77A88AB9 51 Bytes  [ 85, C0, 89, 45, C0, 0F, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLFromStore + 2                                                                              77A88AED 64 Bytes  [ FF, 75, C0, 8B, F8, E8, B9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCTLToStore + 38                                                                        77A88BF6 64 Bytes  [ C0, 89, 45, D4, 0F, 85, 69, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 2B                                                                            77A88C37 41 Bytes  [ 45, D0, 29, 45, B0, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 55                                                                            77A88C61 333 Bytes  [ 55, 8B, EC, 83, EC, 14, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1A3                                                                           77A88DAF 18 Bytes  [ 07, 80, FF, 15, 4C, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1B6                                                                           77A88DC2 20 Bytes  [ 83, FF, 04, 8B, 75, 0C, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1CB                                                                           77A88DD7 4 Bytes  [ FF, 6A, 00, 6A ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 33                                                                   77A892AA 73 Bytes  [ 00, 68, 05, 20, 09, 80, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 7D                                                                   77A892F4 6 Bytes  [ FF, 75, 14, 89, 75, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 84                                                                   77A892FB 48 Bytes  [ 75, 10, 53, FF, 76, 14, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 34                                                                   77A8933D 69 Bytes  [ 45, 14, 33, F6, 3B, C6, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 7A                                                                   77A89383 35 Bytes  [ DB, 89, 5D, E0, 89, 5D, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 9E                                                                   77A893A7 33 Bytes  [ 09, 83, 4D, FC, FF, E9, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + C0                                                                   77A893C9 34 Bytes  [ 0C, 8B, 4E, 04, 53, 52, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + E3                                                                   77A893EC 59 Bytes  [ BB, FD, FF, 85, C0, 74, B5, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + 2                                                                 77A895AF 55 Bytes  [ 89, 45, E4, 39, 7D, E4, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + 3A                                                                77A895E7 61 Bytes  [ 15, 4C, 12, A5, 77, 8B, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + C9                                                                77A89676 12 Bytes  [ 8B, 7E, 14, EB, 0C, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + D6                                                                77A89683 3 Bytes  [ D3, 81, FD ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + DA                                                                77A89687 15 Bytes  [ 85, FF, 75, F0, FF, 75, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 2                                                              77A8994A 29 Bytes  [ 3B, CF, 0F, 86, B0, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 20                                                             77A89968 28 Bytes  [ 00, 00, 00, 6A, 02, 57, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 3D                                                             77A89985 91 Bytes  [ 00, 00, FF, 75, 1C, 56, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 99                                                             77A899E1 56 Bytes  [ 75, 18, 51, FF, 75, 0C, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + D2                                                             77A89A1A 29 Bytes  [ 8B, FF, 55, 8B, EC, 51, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 1A                                                               77A89A38 59 Bytes  [ 75, 14, FF, 75, 10, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 56                                                               77A89A74 80 Bytes  [ 75, 10, FF, 75, 0C, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + A7                                                               77A89AC5 113 Bytes  CALL 77A89374 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 11B                                                              77A89B39 1 Byte  [ 89 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 11D                                                              77A89B3B 76 Bytes  [ F0, 89, 75, F4, 74, 07, C7, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 1C                                                 77A89C5D 95 Bytes  [ 6A, 00, 6A, FF, 6A, 04, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 7C                                                 77A89CBD 125 Bytes  [ F8, 68, 8D, 06, A6, 77, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + FA                                                 77A89D3B 2 Bytes  [ 46, 24 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + FD                                                 77A89D3E 25 Bytes  [ 7E, 1C, 53, 89, 45, 0C, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 117                                                77A89D58 71 Bytes  [ 15, 08, 12, A5, 77, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreA                                                                                 77A89E0A 42 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreA + 2B                                                                            77A89E35 69 Bytes  [ 74, 37, 84, E4, 79, 10, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreW + 32                                                                            77A89E7B 25 Bytes  [ 75, 04, 33, FF, EB, 4F, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 8                                                          77A89E95 8 Bytes  [ 8B, F8, 85, FF, 75, 0D, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 11                                                         77A89E9E 24 Bytes  [ D6, 85, C0, 75, 01, 47, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 2A                                                         77A89EB7 3 Bytes  [ 75, 1C, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 2E                                                         77A89EBB 69 Bytes  [ FC, FF, 75, F8, 53, E8, 2B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 2A                                                         77A89F01 43 Bytes  [ 89, 7D, F8, 89, 7D, F4, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 56                                                         77A89F2D 3 Bytes  [ 00, 01, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 5A                                                         77A89F31 91 Bytes  [ 03, 09, 45, 0C, 8B, 4D, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + B6                                                         77A89F8D 82 Bytes  [ 83, F8, FF, 89, 45, FC, 0F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 109                                                        77A89FE0 109 Bytes  CALL 77A869EE C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 4B                                                                         77A8A3A6 40 Bytes  [ 75, 0C, FF, 77, 08, E8, 34, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 74                                                                         77A8A3CF 3 Bytes  [ 9D, DD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 7A                                                                         77A8A3D5 2 Bytes  [ 74, 32 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + A2                                                                         77A8A3FD 58 Bytes  CALL 77A90535 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + DD                                                                         77A8A438 86 Bytes  [ 75, 10, 33, FF, FF, 75, 0C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + 4                                                                               77A8A52F 98 Bytes  [ 45, 10, 83, C7, 04, 3B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + 67                                                                              77A8A592 96 Bytes  [ 1A, AB, FC, FF, FF, 75, F0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + C8                                                                              77A8A5F3 22 Bytes  [ F0, 85, F6, 74, 14, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + DF                                                                              77A8A60A 9 Bytes  [ 8B, F0, FF, 75, 0C, E8, 9C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + E9                                                                              77A8A614 76 Bytes  [ EB, 14, 68, 2C, 94, A8, 77, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 4                                                                77A8A872 16 Bytes  [ 51, 14, 3B, 57, 10, 74, 11, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 15                                                               77A8A883 80 Bytes  CALL 77A8A707 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 66                                                               77A8A8D4 121 Bytes  [ 68, 07, 20, 09, 80, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + E0                                                               77A8A94E 127 Bytes  [ 4D, 10, 8B, 01, A9, F8, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 61                                                            77A8A9CE 9 Bytes  [ E4, 50, 56, 56, 68, 00, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 6B                                                            77A8A9D8 8 Bytes  [ 02, 8D, 45, D4, 50, E8, 95, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 74                                                            77A8A9E1 60 Bytes  [ FF, 85, C0, 74, 05, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + B1                                                            77A8AA1E 96 Bytes  [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 113                                                           77A8AA80 68 Bytes  [ 85, C0, 74, 17, 8B, 45, 1C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProvForEncrypt + 2B                                                            77A8ABE5 32 Bytes  [ 75, E4, 8B, F0, FF, 15, 88, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProvForEncrypt + 11B                                                           77A8ACD5 82 Bytes  [ 83, 7E, 04, 01, 0F, 85, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 4F                                                                 77A8AD3B 2 Bytes  [ 4D, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 52                                                                 77A8AD3E 37 Bytes  [ 75, E4, 8B, C1, C1, E9, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 78                                                                 77A8AD64 10 Bytes  [ 53, EB, 27, FF, 75, EC, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 83                                                                 77A8AD6F 38 Bytes  [ 8B, F8, 3B, FE, 74, 7E, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + AA                                                                 77A8AD96 26 Bytes  [ 8B, 75, FC, EB, 33, E8, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 12                                                                            77A8AE94 1 Byte  [ FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 14                                                                            77A8AE96 40 Bytes  CALL 77A8AE07 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 3D                                                                            77A8AEBF 4 Bytes  [ F6, 74, 08, 6A ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 7C                                                                            77A8AEFE 3 Bytes  [ 18, EB, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 80                                                                            77A8AF02 45 Bytes  [ 85, C0, 75, 02, 33, DB, 85, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 4                                                                    77A8B050 18 Bytes  [ 36, 8B, C8, 8B, D1, C1, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 17                                                                   77A8B063 2 Bytes  [ A4, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 1A                                                                   77A8B066 10 Bytes  [ 10, 8B, 75, EC, 83, C6, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 25                                                                   77A8B071 7 Bytes  CALL ED9525FF 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 2D                                                                   77A8B079 29 Bytes  [ 4D, F4, 29, 4D, FC, 85, C9, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 21                                                                                 77A8B293 29 Bytes  [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 3F                                                                                 77A8B2B1 72 Bytes  [ 07, 80, FF, 15, 4C, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 88                                                                                 77A8B2FA 60 Bytes  [ 39, 3B, 89, 4D, F8, 76, 1B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + D3                                                                                 77A8B345 23 Bytes  [ 4D, FC, 41, 3B, 4D, F4, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + EB                                                                                 77A8B35D 20 Bytes  [ 55, 8B, EC, 51, 51, 83, 7D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 30                                                                          77A8B3C0 18 Bytes  [ EC, 51, 8D, 45, FC, 50, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 43                                                                          77A8B3D3 26 Bytes  [ 85, C0, 75, 08, FF, 15, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 5E                                                                          77A8B3EE 35 Bytes  [ 07, B8, 0E, 00, 07, 80, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 82                                                                          77A8B412 1 Byte  [ 15 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 84                                                                          77A8B414 8 Bytes  [ 12, A5, 77, EB, 13, 8B, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfoEx + 5                                                                       77A8BE87 54 Bytes  [ 83, EC, 44, A1, 00, 51, AD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfoEx + 3C                                                                      77A8BEBE 58 Bytes  [ 85, C0, 0F, 84, BB, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfo + 2                                                                         77A8BEF9 8 Bytes  [ 36, FF, 75, D0, E8, 90, 60, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfo + B                                                                         77A8BF02 39 Bytes  JMP 77A8BFE7 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + D                                                                  77A8BF2B 1 Byte  [ CC ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + F                                                                  77A8BF2D 8 Bytes  [ 53, 53, FF, 75, C0, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + 18                                                                 77A8BF36 56 Bytes  [ 15, A0, 10, A5, 77, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + 52                                                                 77A8BF70 184 Bytes  [ 0C, 89, 7D, C8, FF, 75, CC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 66                                                                      77A8C029 50 Bytes  [ 15, F7, 45, FC, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 99                                                                      77A8C05C 62 Bytes  [ 59, 33, C0, 8D, 7D, E0, F3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + D8                                                                      77A8C09B 51 Bytes  [ 75, 0C, FF, 75, 08, E8, DD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 10C                                                                     77A8C0CF 12 Bytes  [ E4, 57, FF, 75, 0C, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 119                                                                     77A8C0DC 113 Bytes  [ 85, C0, 75, 09, 8B, 45, 28, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 27                                                                    77A8C14E 13 Bytes  [ 8D, 45, F8, 50, 8D, 45, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 35                                                                    77A8C15C 147 Bytes  [ 8D, 5D, F8, 8B, 75, 0C, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + C9                                                                    77A8C1F0 135 Bytes  [ 39, 7D, 10, 76, 3C, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 151                                                                   77A8C278 8 Bytes  [ 45, 0C, 8B, 08, 85, C9, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 15A                                                                   77A8C281 10 Bytes  [ 70, 04, 57, 89, 4D, 0C, 76, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 2E                                                                 77A8C530 12 Bytes  [ 75, 08, FF, D6, 85, C0, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 3B                                                                 77A8C53D 128 Bytes  [ 1E, 00, 00, 21, 7D, F4, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + BD                                                                 77A8C5BF 57 Bytes  [ 08, FF, 15, 84, 12, A5, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + F7                                                                 77A8C5F9 238 Bytes  [ 08, 8B, F8, 8B, C1, C1, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 1E6                                                                77A8C6E8 59 Bytes  [ 3B, C6, 75, 0D, 6A, 02, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignature + 25                                                                 77A8C724 32 Bytes  [ 8D, 45, F0, 50, 8D, 45, F4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + 10                                                                          77A8C745 7 Bytes  [ 55, 10, 56, FF, 75, E8, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + C5                                                                          77A8C7FA 36 Bytes  [ 30, 5E, 8B, C3, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + EA                                                                          77A8C81F 18 Bytes  [ 75, 10, 89, 01, 8B, 4D, 2C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + FD                                                                          77A8C832 23 Bytes  [ 5D, C2, 28, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + 115                                                                         77A8C84A 7 Bytes  [ 28, 33, DB, 57, 8B, 7D, 20 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 4A                                                                   77A8C8D7 54 Bytes  [ 8B, 45, 2C, 89, 1E, 89, 1F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 82                                                                   77A8C90F 1 Byte  [ FC ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 85                                                                   77A8C912 18 Bytes  [ F4, 0F, 84, E0, 01, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 98                                                                   77A8C925 60 Bytes  [ 50, 51, 6A, 27, FF, 75, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + D5                                                                   77A8C962 61 Bytes  [ 08, 0F, 84, 89, 01, 00, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 35                                                                         77A8DE94 1 Byte  [ F6 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 37                                                                         77A8DE96 62 Bytes  [ 07, 08, 04, 11, 33, F6, 41, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 76                                                                         77A8DED5 94 Bytes  [ FF, EB, 08, FF, 75, 0C, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 3E                                                                       77A8DF34 36 Bytes  [ 10, 50, 6A, 04, 6A, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 63                                                                       77A8DF59 15 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 74                                                                       77A8DF6A 1 Byte  [ 08 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 76                                                                       77A8DF6C 94 Bytes  [ 8D, 45, 0C, 50, 6A, 00, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + D5                                                                       77A8DFCB 30 Bytes  [ 57, 8D, 45, F8, 50, 57, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A                                                                        77A8E0D3 142 Bytes  [ C7, 5F, 5E, 5B, C9, C2, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + 99                                                                       77A8E162 2 Bytes  [ F4, 57 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + 9C                                                                       77A8E165 2 Bytes  [ 47, 6F ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A0                                                                       77A8E169 3 Bytes  [ FF, 75, F8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A4                                                                       77A8E16D 21 Bytes  [ 15, 10, 10, A5, 77, 39, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 27                                                                     77A8E204 101 Bytes  [ FF, 8B, D8, 83, FB, FF, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + AC                                                                     77A8E289 7 Bytes  [ 90, 90, 90, 90, 8B, FF, 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + B4                                                                     77A8E291 159 Bytes  [ EC, 83, EC, 5C, A1, 00, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 16C                                                                    77A8E349 66 Bytes  [ 57, 6A, 04, 53, 53, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 1AF                                                                    77A8E38C 7 Bytes  [ 53, 68, 2C, BA, A5, 77, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 45                                                                             77A8E512 21 Bytes  [ 8B, F0, 8B, 45, C0, 56, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 5B                                                                             77A8E528 3 Bytes  [ 6E, 5A, FE ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 5F                                                                             77A8E52C 5 Bytes  [ 85, C0, 0F, 85, 98 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 66                                                                             77A8E533 80 Bytes  [ 00, FF, 75, CC, 03, DE, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + B7                                                                             77A8E584 23 Bytes  [ 33, F6, 39, 75, D0, 76, 20, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 64                                                                           77A8EB99 1 Byte  [ 55 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 66                                                                           77A8EB9B 44 Bytes  [ EC, 8B, 45, 08, 56, 33, F6, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 93                                                                           77A8EBC8 89 Bytes  [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + ED                                                                           77A8EC22 20 Bytes  [ 5E, 5F, 5D, C2, 0C, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 102                                                                          77A8EC37 63 Bytes  [ F6, 74, 17, 8B, 45, 0C, 83, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 1                                                                             77A905C1 27 Bytes  [ F0, 85, F6, 74, 31, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 2A                                                                            77A905EA 82 Bytes  [ EB, 0D, 68, 57, 00, 07, 80, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 113                                                                           77A906D3 12 Bytes  [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 120                                                                           77A906E0 33 Bytes  [ AD, 77, 56, 8B, 75, 14, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 142                                                                           77A90702 10 Bytes  [ E4, FF, 75, 10, 89, 45, DC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 10                                                                              77A90852 110 Bytes  [ 98, 8B, 45, 8C, FF, 75, A4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 7F                                                                              77A908C1 112 Bytes  [ 33, C0, 5E, 40, 5B, E8, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + F0                                                                              77A90932 7 Bytes  [ A6, 77, 57, E8, C2, DD, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + F8                                                                              77A9093A 13 Bytes  [ 85, 5E, 28, 89, 45, 10, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 106                                                                             77A90948 167 Bytes  [ A1, 64, 54, AD, 77, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 11                                                                                  77A9190E 2 Bytes  [ 24, 00 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 14                                                                                  77A91911 58 Bytes  [ 66, 89, 11, 03, CF, FF, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 4F                                                                                  77A9194C 22 Bytes  [ 4D, 0C, 8B, 01, 8B, 49, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 66                                                                                  77A91963 33 Bytes  CALL 8F1FF4ED 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 88                                                                                  77A91985 96 Bytes  [ 74, 08, 8B, 4D, 10, 66, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + 5B                                                                                  77A919E9 91 Bytes  [ 90, 8B, FF, 55, 8B, EC, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + B7                                                                                  77A91A45 7 Bytes  [ 20, 51, B9, 84, 0A, A9, 77 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + BF                                                                                  77A91A4D 3 Bytes  [ 48, FF, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + C3                                                                                  77A91A51 60 Bytes  [ 85, C0, 75, 11, B8, 21, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + 100                                                                                 77A91A8E 19 Bytes  [ 2D, 00, 2E, 00, 2F, 00, 3A, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + A                                                                                   77A91CB9 18 Bytes  [ 83, FF, 0B, 0F, 84, 80, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 1E                                                                                  77A91CCD 44 Bytes  [ 85, DB, 74, 32, FF, 75, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 4B                                                                                  77A91CFA 8 Bytes  [ 01, 8B, 4D, FC, 66, 83, 24, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 54                                                                                  77A91D03 89 Bytes  [ 8B, 4D, FC, 33, C0, 01, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + AE                                                                                  77A91D5D 2 Bytes  [ FF, 10 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 2                                                                                   77A921FF 54 Bytes  [ FF, 5F, 5E, C9, C2, 10, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 39                                                                                  77A92236 24 Bytes  [ 04, FD, 07, 00, 00, 00, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 52                                                                                  77A9224F 20 Bytes  [ 3E, 89, 55, 14, EB, 73, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 67                                                                                  77A92264 62 Bytes  [ 45, F8, 8B, C6, C1, E0, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + A6                                                                                  77A922A3 35 Bytes  CALL 77A92181 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 68                                                                              77A92671 75 Bytes  [ 75, F0, 8D, 45, F4, 53, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + B4                                                                              77A926BD 86 Bytes  [ 79, 04, 89, 10, 89, 70, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 10C                                                                             77A92715 53 Bytes  [ 00, 20, C7, 45, EC, F4, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 142                                                                             77A9274B 64 Bytes  CALL 77A9269A C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 183                                                                             77A9278C 1 Byte  [ 50 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 4                                                                               77A928D5 60 Bytes  [ 45, FC, 5E, 40, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 41                                                                              77A92912 20 Bytes  [ 71, 04, C1, E0, 08, 6A, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 56                                                                              77A92927 68 Bytes  [ F0, FF, 75, 14, FF, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 3A                                                                              77A9296C 95 Bytes  [ 15, A8, 12, A5, 77, 83, F8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 9A                                                                              77A929CC 1 Byte  [ 75 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 9C                                                                              77A929CE 106 Bytes  CALL 77A92947 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 107                                                                             77A92A39 27 Bytes  [ 85, C0, 5F, 74, 08, 8B, 40, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 123                                                                             77A92A55 5 Bytes  [ 90, 90, 90, 90, 90 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 1                                                                               77A92C14 7 Bytes  [ FA, EB, 50, 83, 7D, FC, 01 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 9                                                                               77A92C1C 4 Bytes  [ 2E, 66, 3B, D8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + E                                                                               77A92C21 18 Bytes  [ 7A, 66, 83, FB, 22, 75, 3F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 21                                                                              77A92C34 5 Bytes  [ D0, EB, 30, 8B, 4D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 27                                                                              77A92C3A 89 Bytes  [ 8B, C2, 2B, C7, D1, F8, 89, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 2                                                                           77A93730 68 Bytes  [ 85, C0, 89, 45, F0, 75, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 47                                                                          77A93775 24 Bytes  CALL 77A93316 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 60                                                                          77A9378E 52 Bytes  [ 89, 45, F4, 8D, 45, FC, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 95                                                                          77A937C3 3 Bytes  JMP 03A933E4 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 99                                                                          77A937C7 71 Bytes  [ 8B, F0, 85, F6, 74, 2C, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetAsyncParam + 12                                                                              77A938F4 3 Bytes  [ DF, 1B, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetAsyncParam + 16                                                                              77A938F8 112 Bytes  [ 8B, F8, 85, FF, 74, 13, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetMessageSignerCount + 25                                                                      77A9396B 112 Bytes  CALL 77A9183F C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage                                                                                     77A939E0 42 Bytes  [ 85, F6, 74, 29, 8B, 0A, B8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 2C                                                                                77A93A0C 19 Bytes  [ 32, C3, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 40                                                                                77A93A20 38 Bytes  [ 7D, 20, C7, 45, D8, 27, 20, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 67                                                                                77A93A47 91 Bytes  [ FF, 75, 08, FF, 55, DC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + D0                                                                                77A93AB0 17 Bytes  [ C4, 89, 45, E0, 83, 4D, FC, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncryptMessage + 2E                                                                             77A942D9 9 Bytes  [ 45, 10, 50, 57, 53, 89, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncryptMessage + 38                                                                             77A942E3 81 Bytes  [ 62, FD, FF, 85, C0, 0F, 84, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageHash + 1                                                                           77A94335 2 Bytes  [ 47, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageHash + 4                                                                           77A94338 56 Bytes  [ 38, 83, 7F, 0C, 02, 72, 66, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageHash + 10                                                                  77A94371 25 Bytes  [ 00, 8B, 40, 04, 6A, 03, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageHash + 2A                                                                  77A9438B 55 Bytes  [ 01, 00, 53, 53, FF, 75, E0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 33                                                                         77A943C3 3 Bytes  [ 46, 0C, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 37                                                                         77A943C7 41 Bytes  [ E4, 89, 46, 04, 33, C0, 40, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 62                                                                         77A943F2 2 Bytes  [ FC, 8B ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 65                                                                         77A943F5 40 Bytes  [ 0C, 8B, 40, 10, 8B, 00, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 8E                                                                         77A9441E 64 Bytes  CALL B069C774 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 49                                                              77A94598 65 Bytes  [ 56, 8B, F1, 83, 66, 18, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 8B                                                              77A945DA 100 Bytes  [ 75, 08, FF, 15, 84, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + F0                                                              77A9463F 12 Bytes  [ 76, 04, FF, 36, FF, D0, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 127                                                             77A94676 77 Bytes  [ 10, 8B, 4D, 08, 83, 61, 0C, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 175                                                             77A946C4 53 Bytes  [ 71, 18, EB, 03, 8B, 71, 1C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 3B                                                                                77A94D0C 14 Bytes  [ 46, 56, 89, 45, E0, E8, E9, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 4A                                                                                77A94D1B 1 Byte  [ 40 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 4C                                                                                77A94D1D 154 Bytes  [ EB, 02, 33, C0, 3D, 01, AA, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 58                                                                      77A94DB8 95 Bytes  [ FC, 8B, 4D, E0, 89, 7B, 40, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + B8                                                                      77A94E18 35 Bytes  [ 51, 18, 89, 50, 04, 8B, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + F7                                                                      77A94E57 9 Bytes  [ EB, 0C, FF, 75, E4, E8, 4F, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 101                                                                     77A94E61 130 Bytes  [ 83, 65, E4, 00, 8B, 45, E4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 184                                                                     77A94EE4 39 Bytes  [ 15, 4C, 12, A5, 77, 6A, 11, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignature + 22                                                                     77A951F4 19 Bytes  [ 08, FF, 15, 08, 12, A5, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageSignature + 18                                                             77A9521E 19 Bytes  [ 0D, 53, FF, 15, 4C, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptMessage + 19                                                                             77A95255 15 Bytes  [ 6A, 00, FF, 75, 10, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptMessage + 29                                                                             77A95265 11 Bytes  [ 83, 7D, FC, 00, 75, 04, 33, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + A                                                            77A95279 32 Bytes  [ F0, 85, F6, 74, 21, 8D, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 31                                                           77A952A0 54 Bytes  [ C0, 5E, C9, C2, 0C, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 68                                                           77A952D7 54 Bytes  [ 1C, 8B, 4E, 20, 8B, C2, 83, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 9F                                                           77A9530E 7 Bytes  [ 83, 7D, DC, 00, 8B, F8, 74 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + A7                                                           77A95316 3 Bytes  [ FF, 75, DC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeMessage + D                                                                               77A95375 181 Bytes  [ 1C, FF, 75, 18, FF, 75, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 84                                                                               77A9542B 21 Bytes  CALL 77A963A5 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 9A                                                                               77A95441 45 Bytes  [ 00, 6A, 1C, 33, C0, 83, 3B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + C8                                                                               77A9546F 5 Bytes  [ 89, B5, FC, FE, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + CE                                                                               77A95475 62 Bytes  [ 72, 19, 8D, 73, 20, 8B, 06, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 10D                                                                              77A954B4 7 Bytes  [ 43, 08, 89, 85, 70, FF, FF ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + B                                                                         77A9B8B4 8 Bytes  [ 0C, 8D, 47, 08, 50, E8, 22, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + 15                                                                        77A9B8BE 98 Bytes  [ 8B, 4D, F8, 4E, 83, C7, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + 78                                                                        77A9B921 93 Bytes  [ 8B, F0, 85, F6, 74, 29, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDFunction + 3B                                                                        77A9B97F 97 Bytes  [ E1, F8, 2B, D1, 89, 75, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + F                                                                       77A9B9E1 18 Bytes  [ 8B, 45, 18, 5F, 89, 30, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 22                                                                      77A9B9F4 98 Bytes  [ 55, 8B, EC, 53, 8B, 5D, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 85                                                                      77A9BA57 25 Bytes  [ 83, C6, 14, 85, FF, 77, D4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 9F                                                                      77A9BA71 2 Bytes  [ EC, 56 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + A2                                                                      77A9BA74 165 Bytes  [ 75, 08, 8B, 46, 04, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + 77                                                                 77A9BBBE 11 Bytes  [ 75, 18, FF, 75, 14, 50, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + 84                                                                 77A9BBCB 39 Bytes  [ 8B, F0, 8D, 45, E0, 50, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + AC                                                                 77A9BBF3 32 Bytes  [ C6, 5E, C9, C2, 1C, 00, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + CD                                                                 77A9BC14 23 Bytes  [ FC, 79, 06, 83, 65, 14, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + E5                                                                 77A9BC2C 27 Bytes  [ 8B, 5D, 0C, 8B, 7D, 08, 8D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 37                                                               77A9BCF0 76 Bytes  CALL 7C20BC45 C:\Programmi\File comuni\Ahead\Lib\MFC71.DLL (MFCDLL Shared Library - Retail Version/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 84                                                               77A9BD3D 44 Bytes  [ 19, FF, 75, 20, 8D, 45, E8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + B1                                                               77A9BD6A 21 Bytes  CALL 77A9BA6A C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + C7                                                               77A9BD80 126 Bytes  [ FF, 55, 8B, EC, 51, 53, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 147                                                              77A9BE00 18 Bytes  [ FC, 89, 03, 5F, 33, C0, 5E, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDInfo + 4E                                                                            77A9BF71 4 Bytes  [ 85, C0, 89, 42 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDInfo + 53                                                                            77A9BF76 252 Bytes  [ 89, 72, 08, 76, 10, 8B, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 9B                                                                          77A9C073 4 Bytes  [ FF, 75, 14, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + F5                                                                          77A9C0CD 38 Bytes  [ 80, 74, 05, 8B, 45, 1C, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 11C                                                                         77A9C0F4 2 Bytes  [ F0, 8D ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 11F                                                                         77A9C0F7 26 Bytes  CALL 77A9BA6B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 13C                                                                         77A9C114 46 Bytes  [ 8B, 10, 8B, 4D, 14, 56, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + 5E                                                                          77A9C4B6 64 Bytes  [ FF, 85, C0, 74, 1C, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + 9F                                                                          77A9C4F7 4 Bytes  [ 78, FC, 89, 38 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + A4                                                                          77A9C4FC 31 Bytes  [ 55, FC, 8B, 52, 04, 8B, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + C4                                                                          77A9C51C 7 Bytes  [ 0A, 72, D0, 8D, 45, F0, 89 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + CC                                                                          77A9C524 4 Bytes  [ F8, FF, 75, 24 ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 29                                                                                77A9CEA7 50 Bytes  [ 76, 04, FF, D7, 8B, D8, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 5C                                                                                77A9CEDA 24 Bytes  [ 5F, 5B, EB, 0D, 68, 57, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 75                                                                                77A9CEF3 15 Bytes  [ C9, C3, 90, 90, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 85                                                                                77A9CF03 21 Bytes  [ 75, 14, FF, 75, 10, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 9B                                                                                77A9CF19 20 Bytes  [ FF, 5D, C2, 14, 00, 90, 90, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 9A                                                                               77A9D271 96 Bytes  [ 75, 08, 56, FF, 55, 0C, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + FB                                                                               77A9D2D2 55 Bytes  CALL C534D6C2 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 133                                                                              77A9D30A 10 Bytes  [ 89, 75, F4, FF, D3, 8D, 44, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 13E                                                                              77A9D315 8 Bytes  [ F0, 03, C6, 50, E8, 92, 81, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 147                                                                              77A9D31E 92 Bytes  [ 8B, D8, 85, DB, 0F, 84, 82, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 21                                                                                 77AA5CF3 6 Bytes  [ E4, 74, 05, FF, 75, E4 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 28                                                                                 77AA5CFA 46 Bytes  [ D6, 39, 5D, E0, 74, 05, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 57                                                                                 77AA5D29 39 Bytes  [ 75, F4, FF, D6, 39, 5D, FC, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 7F                                                                                 77AA5D51 17 Bytes  [ 55, 8B, EC, 81, EC, 3C, 04, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 92                                                                                 77AA5D64 112 Bytes  [ FC, 8B, 45, 14, 53, 56, 33, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 15                                                                           77AA71B2 29 Bytes  CALL 77A82D4D C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 33                                                                           77AA71D0 23 Bytes  JMP 77AA725C C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 4B                                                                           77AA71E8 112 Bytes  [ 57, 57, 57, 6A, 02, 57, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + BD                                                                           77AA725A 33 Bytes  [ F8, FF, D3, 5B, 8B, C6, 5E, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + DF                                                                           77AA727C 71 Bytes  [ 00, A1, 00, 51, AD, 77, 8B, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 17                                                                        77AA8398 1 Byte  [ 4F ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 19                                                                        77AA839A 46 Bytes  [ 43, 00, 20, 00, 4D, 00, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 49                                                                        77AA83CA 15 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 59                                                                        77AA83DA 1 Byte  [ A1 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 5B                                                                        77AA83DC 40 Bytes  [ 51, AD, 77, 53, 8B, 5D, 10, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUnregisterSmartCardStore + 2                                                                  77AA84C6 3 Bytes  [ FF, 74, 1E ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUnregisterSmartCardStore + 6                                                                  77AA84CA 77 Bytes  [ B5, 64, FD, FF, FF, 50, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 34                                                                 77AA8518 16 Bytes  [ FF, 00, 66, 83, A5, 6C, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 45                                                                 77AA8529 155 Bytes  [ 8B, 46, 0C, 83, C0, 20, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + E1                                                                 77AA85C5 26 Bytes  [ 83, 78, 04, 00, C7, 85, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + FC                                                                 77AA85E0 36 Bytes  [ FF, 85, C0, 89, 85, 60, FD, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 121                                                                77AA8605 14 Bytes  [ 74, 3D, 8B, 95, 60, FD, FF, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 2                                                                   77AA866C 9 Bytes  [ 85, C0, 74, 3B, FF, B5, 64, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + C                                                                   77AA8676 26 Bytes  [ 8D, 85, 6C, FF, FF, FF, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 27                                                                  77AA8691 64 Bytes  [ FF, FF, 50, 8D, 47, 04, 68, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 68                                                                  77AA86D2 3 Bytes  [ 75, F1, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 6D                                                                  77AA86D7 11 Bytes  [ 85, 68, FD, FF, FF, 8D, 1C, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallOssGlobal + 19                                                                         77AA87C2 58 Bytes  [ 50, 8D, 46, 14, 68, 1F, 25, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 32                                                                             77AA8822 110 Bytes  [ 8D, 45, A4, 50, 75, 0A, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + A1                                                                             77AA8891 19 Bytes  [ CA, 83, E1, 03, F3, A4, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + B5                                                                             77AA88A5 168 Bytes  [ 33, C0, 81, 7D, 10, 1A, 18, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 242                                                                            77AA8A32 3 Bytes  [ 83, 4D, FC ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 246                                                                            77AA8A36 34 Bytes  [ FF, 75, E4, FF, 15, 4C, 12, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 7A                                                                  77AB1345 40 Bytes  [ FF, 8D, 43, 5C, 50, 6A, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + A4                                                                  77AB136F 18 Bytes  [ F6, 03, 80, 75, 04, 83, 63, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + B7                                                                  77AB1382 101 Bytes  [ D6, F7, D8, 1B, C0, F7, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 11D                                                                 77AB13E8 57 Bytes  [ 90, 90, 90, 90, 90, C2, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 157                                                                 77AB1422 54 Bytes  [ F0, 85, F6, 74, 2A, 8D, 45, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 18                                                                               77AB327B 83 Bytes  [ 43, 04, 89, 45, EC, EB, 61, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 6C                                                                               77AB32CF 71 Bytes  [ 75, D4, FF, 75, DC, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + B4                                                                               77AB3317 38 Bytes  [ E4, 50, A5, 8D, 45, B4, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + DB                                                                               77AB333E 45 Bytes  CALL 77A92B2B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 109                                                                              77AB336C 124 Bytes  CALL F52F0A70 
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 3E                                                           77AB4A21 29 Bytes  [ 55, 8B, EC, 83, EC, 0C, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 5C                                                           77AB4A3F 1 Byte  [ 45 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 5E                                                           77AB4A41 69 Bytes  [ 74, 1D, FF, 75, 10, FF, 75, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + A4                                                           77AB4A87 29 Bytes  [ 85, C0, 7D, 19, 68, 05, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + C2                                                           77AB4AA5 5 Bytes  [ 75, 08, FF, 75, FC ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToEncode + 6                                                                             77AB8203 148 Bytes  [ 45, F0, 89, 41, 08, 8B, 45, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToEncode + 9B                                                                            77AB8298 185 Bytes  [ 8B, 43, 08, 89, 45, CC, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + CB                                                                             77AB8387 62 Bytes  CALL CF1393FF 
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 10A                                                                            77AB83C6 38 Bytes  [ F8, 83, 3E, 24, 72, 1A, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 131                                                                            77AB83ED 203 Bytes  [ 8B, 4E, 14, 03, CA, 03, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 1FD                                                                            77AB84B9 27 Bytes  [ 4D, F4, 89, 41, 04, 03, 02, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 219                                                                            77AB84D5 43 Bytes  [ 7E, 14, 00, 0F, 84, 87, 00, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetAndVerifySigner + 18                                                                      77AB85F8 81 Bytes  [ 57, 2C, C7, 47, 30, 02, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetAndVerifySigner + 6A                                                                      77AB864A 144 Bytes  [ 85, C0, 74, 19, 83, 7F, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 71                                                                        77AB8701 194 Bytes  [ 55, 8B, EC, 83, EC, 14, 53, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 134                                                                       77AB87C4 37 Bytes  [ 47, C7, 43, 30, 05, 00, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 15A                                                                       77AB87EA 75 Bytes  [ 75, 18, 89, 43, 44, E8, DB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 1A6                                                                       77AB8836 33 Bytes  [ FF, 3B, C7, 59, 74, 0A, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 1C8                                                                       77AB8858 10 Bytes  [ C8, 3B, CF, 74, 12, 89, 79, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveProvider + D5                                                                          77ABDD53 112 Bytes  [ C6, 5E, 5B, C9, C2, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 28                                                                             77ABDDC6 10 Bytes  [ 00, 75, 35, 83, 7D, 08, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 33                                                                             77ABDDD1 19 Bytes  [ 44, 00, 74, 04, A8, 40, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 48                                                                             77ABDDE6 1 Byte  [ C7 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 4C                                                                             77ABDDEA 17 Bytes  [ 6A, 00, 53, FF, 75, 0C, 56, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 5E                                                                             77ABDDFC 106 Bytes  [ 00, 00, 33, D2, 39, 55, 14, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 2F                                                                        77ABDF92 22 Bytes  [ 74, 14, FF, 75, 08, 83, C7, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 46                                                                        77ABDFA9 4 Bytes  [ 15, 08, 12, A5 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 4B                                                                        77ABDFAE 17 Bytes  [ 89, 45, F8, 33, F6, EB, 03, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 5D                                                                        77ABDFC0 116 Bytes  [ 5F, 8B, C6, 5E, 5B, C9, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveSignedDataMsg + 3D                                                                     77ABE035 17 Bytes  [ 00, 56, 68, 67, BD, AB, 77, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveSignedDataMsg + 4F                                                                     77ABE047 81 Bytes  [ 00, 00, 50, 8D, 46, 78, 50, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPCreateIndirectData + 63                                                                      77ABE0E1 13 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPCreateIndirectData + 72                                                                      77ABE0F0 4 Bytes  [ 35, 54, 50, AD ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + 70                                                       77ABE17D 20 Bytes  [ 62, 8B, 03, 89, 87, C4, 00, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + C7                                                       77ABE1D4 6 Bytes  [ 80, 4E, 7E, 01, 50, E8 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + CE                                                       77ABE1DB 28 Bytes  [ E2, FA, FF, EB, 10, 8B, 86, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + EB                                                       77ABE1F8 36 Bytes  [ 7D, 0C, 00, 74, 05, 0B, C2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + 110                                                      77ABE21D 100 Bytes  [ EB, 0C, 83, 3F, 00, 75, 04, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 4E                                                                                77ABF104 149 Bytes  [ C9, C2, 0C, 00, 90, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + E4                                                                                77ABF19A 14 Bytes  CALL 77A82D4B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + F3                                                                                77ABF1A9 14 Bytes  [ 0F, 84, 1B, 01, 00, 00, 89, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 102                                                                               77ABF1B8 40 Bytes  [ FF, 75, BC, FF, 15, 54, 13, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 12C                                                                               77ABF1E2 48 Bytes  [ C0, 56, FF, 15, AC, 12, A5, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8                                                                                     77ABF2F9 64 Bytes  [ 90, 33, C0, 40, C3, 90, 90, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 42                                                                                77ABF33B 11 Bytes  [ FF, A3, E2, AB, 77, B6, E2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 4E                                                                                77ABF347 68 Bytes  [ FF, FA, E2, AB, 77, 03, E3, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 94                                                                                77ABF38D 24 Bytes  [ F4, 89, 5D, F8, 89, 5D, F0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + AD                                                                                77ABF3A6 13 Bytes  [ 45, 0C, 53, FF, 75, 10, 25, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + D                                                                               77ABF755 20 Bytes  [ 45, F4, 50, FF, 75, EC, 57, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 23                                                                              77ABF76B 4 Bytes  [ 00, 8D, 45, FF ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 28                                                                              77ABF770 14 Bytes  [ 75, D0, 89, 45, D4, 89, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 38                                                                              77ABF780 452 Bytes  [ 75, 06, C6, 45, FF, 80, EB, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + 9E                                                                              77ABF945 12 Bytes  [ 34, 30, FF, 15, E4, 12, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + AB                                                                              77ABF952 13 Bytes  [ 47, 04, 8B, 44, 06, 08, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + B9                                                                              77ABF960 18 Bytes  [ FF, 30, FF, 70, 04, 6A, 1A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + CD                                                                              77ABF974 89 Bytes  [ F8, 6A, 00, FF, 15, 64, 12, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + 127                                                                             77ABF9CE 214 Bytes  [ FF, FF, EB, 10, C7, 45, F4, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 37                                                                            77ABFAA5 26 Bytes  [ 00, 74, 09, FF, 75, FC, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 52                                                                            77ABFAC0 7 Bytes  [ 5E, 8B, C3, 5B, C9, C2, 10 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 5A                                                                            77ABFAC8 12 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 67                                                                            77ABFAD5 19 Bytes  [ 5D, 08, 53, 6A, 00, FF, 15, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 7B                                                                            77ABFAE9 204 Bytes  [ 0F, 84, E7, 00, 00, 00, 56, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCertificateChain + 9A                                                                   77AC9FBD 21 Bytes  [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCertificateChain + B3                                                                   77AC9FD6 18 Bytes  [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChainEngine + 6                                                                   77ACA01C 57 Bytes  [ F1, 8B, FA, 75, 03, 6A, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 14                                                                77ACA056 22 Bytes  [ DD, F6, 06, 80, 74, 1E, 8B, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 2B                                                                77ACA06D 39 Bytes  [ 00, 80, 57, FF, 15, 10, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 53                                                                77ACA095 22 Bytes  [ 55, 8B, EC, 83, EC, 0C, 85, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 6A                                                                77ACA0AC 2 Bytes  [ 51, 50 ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 6D                                                                77ACA0AF 31 Bytes  [ 75, 08, FF, 15, 6C, 14, A5, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!ChainWlxLogoffEvent                                                                                  77ACA134 103 Bytes  [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 29                                                                    77ACA19C 19 Bytes  [ 15, 54, 14, A5, 77, F7, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 3F                                                                    77ACA1B2 15 Bytes  [ 8B, FF, 55, 8B, EC, 51, 51, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 4F                                                                    77ACA1C2 30 Bytes  [ 58, 8D, 4D, F8, 51, 8D, 4D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 6E                                                                    77ACA1E1 88 Bytes  [ FE, AA, 8D, 46, 04, 50, 6A, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 12                                                                         77ACA23A 17 Bytes  [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 30                                                                         77ACA258 74 Bytes  [ 56, 8B, 75, 08, 85, F6, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 7B                                                                         77ACA2A3 16 Bytes  [ FF, 55, 8B, EC, FF, 75, 10, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 8C                                                                         77ACA2B4 67 Bytes  [ FF, F7, D8, 1B, C0, F7, D8, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + D0                                                                         77ACA2F8 18 Bytes  [ 15, 58, 14, A5, 77, 85, C0, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + F                                                                        77ACA329 29 Bytes  [ 75, 0C, 57, FF, 15, 54, 14, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 2D                                                                       77ACA347 64 Bytes  [ EC, 51, 8B, 45, 0C, 85, C0, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 7F                                                                       77ACA399 27 Bytes  [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 9B                                                                       77ACA3B5 40 Bytes  [ EC, 8B, 45, 08, 85, C0, 74, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + C4                                                                       77ACA3DE 8 Bytes  [ 15, C4, 14, A5, 77, 5E, 5D, ... ]
.text           ...                                                                                                                                           
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!OpenCertPerformanceData + A1                                                                         77ACEC90 13 Bytes  [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!OpenCertPerformanceData + AF                                                                         77ACEC9E 191 Bytes  [ 53, 56, 57, 76, 36, 8B, 5D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 14                                                                      77ACED5E 117 Bytes  [ 4D, FC, 75, 0E, 8B, 45, 08, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 8A                                                                      77ACEDD4 121 Bytes  [ 45, 08, 8B, 50, 34, 85, D2, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 105                                                                     77ACEE4F 23 Bytes  [ 85, DB, 6A, 0F, 59, 8B, FE, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 11D                                                                     77ACEE67 43 Bytes  [ 89, 5E, 04, 89, 46, 08, 8D, ... ]
.text           C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 149                                                                     77ACEE93 65 Bytes  [ 10, 59, 59, FF, 30, FF, 15, ... ]
.text           ...                                                                                                                                           

---- User IAT/EAT - GMER 1.0.14 ----

IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]                                         003A87C1
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]                                        003A8779
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress]                                         003A62D9
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                                           003A6D09
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CloseHandle]                                            003A7C09
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary]                                            003A6E59
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                                           003A6D4E
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileW]                                            003A7629
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalUnlock]                                           003A84FC
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalLock]                                             003A852C
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcessHeap]                                         003A8836
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]                                         003A8401
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DuplicateHandle]                                        003A7B99
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread]                                           003A71D1
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]                                         003A6E0B
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW]                                 003A7011
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent]                                      003A8B62
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!ReadFile]                                               003A7828
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetFilePointer]                                         003A7A95
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx]                                        003A7E8D
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW]                                     003A7D22
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFile]                                          003A7E3B
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW]                                       003A80C7
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile]                                        003A7F85
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA]                                         003A6DBD
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!TerminateProcess]                                       003A7126
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalAlloc]                                            003A85D7
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile]                                        003A7DE4
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileSize]                                            003A7B4C
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!WriteFile]                                              003A7A65
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileType]                                            003A7C99
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetACP]                                                 003A8842
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingA]                                     003A7CB9
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadIconW]                                                003A89C7
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadCursorW]                                              003A8995
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateDialogParamW]                                       003A8AEA
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DialogBoxParamW]                                          003A8B46
IAT             C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadStringW]                                              003A8A33

---- Devices - GMER 1.0.14 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                        89B78FB0

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                        avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device          \FileSystem\Fastfat \FatCdrom                                                                                                                 899370D8
Device          \FileSystem\Udfs \UdfsCdRom                                                                                                                   898721D0
Device          \FileSystem\Udfs \UdfsDisk                                                                                                                    898721D0
Device          \Driver\Tcpip \Device\Ip                                                                                                                      avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device          \Driver\Tcpip \Device\Tcp                                                                                                                     avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device          \FileSystem\Rdbss \Device\FsWrap                                                                                                              897D5C00
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                                            897AE008
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4                                                                                                   897AE008
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                                            897AE008
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c                                                                                                   897AE008
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18                                                                                                  897AE008
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20                                                                                                  897AE008
Device          \Driver\USBSTOR \Device\00000080                                                                                                              sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\USBSTOR \Device\00000081                                                                                                              sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\USBSTOR \Device\00000082                                                                                                              sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\USBSTOR \Device\00000083                                                                                                              sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\USBSTOR \Device\00000084                                                                                                              sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \FileSystem\Srv \Device\LanmanServer                                                                                                          8989E618
Device          \Driver\Tcpip \Device\Udp                                                                                                                     avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device          \Driver\Tcpip \Device\RawIp                                                                                                                   avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device          \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                                                             897D6390
Device          \Driver\Tcpip \Device\IPMULTICAST                                                                                                             avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device          \FileSystem\MRxSmb \Device\LanmanRedirector                                                                                                   897D6390
Device          \FileSystem\Npfs \Device\NamedPipe                                                                                                            8981A250
Device          \FileSystem\Msfs \Device\Mailslot                                                                                                             897D5E18
Device          \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0                                                                                  897D5CE8
Device          \Driver\a347scsi \Device\Scsi\a347scsi1                                                                                                       897D5CE8
Device          \FileSystem\Fastfat \Fat                                                                                                                      899370D8

AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                                      avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device          \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer                                                                                            8990C030
Device          \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer                                                                                             8990C030
Device          \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer                                                                                                 8990C030
Device          \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer                                                                                              8990C030
Device          \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer                                                                                             8990C030
Device          \FileSystem\Cdfs \Cdfs                                                                                                                        899466B8

---- Modules - GMER 1.0.14 ----

Module          _________                                                                                                                                     F73A2000-F73BA000 (98304 bytes)

---- Registry - GMER 1.0.14 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40                                                                                 
Reg             HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName                                   Alcohol 120% (Trial Version)
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Abaddon\x2122 (TrueType)                                                              abaddon.TTF
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Acadian\x2122 (TrueType)                                                              AC______.TTF
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Altenburg\x2122 (TrueType)                                                            ALTEN.TTF
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Asphodel\x2122 (TrueType)                                                             ASPHODEL.TTF
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Balsamo\x2122 (TrueType)                                                              BALSAMO.TTF
Reg             HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName                                                         Alcohol 120% (Trial Version)
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}                               
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}@nakcaiaganokclohnffjminfbaih  0x6B 0x61 0x6E 0x61 ...
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}@maicggelnnkgakdnnoackakloe    0x6B 0x61 0x6E 0x61 ...

---- EOF - GMER 1.0.14 ----
__________________
Se dio avesse voluto che credessimo in lui sarebbe esistito.
Principale: Q6600 (Zalman 9500) - 4core1600twins-sataII - ddr800 2x2gb - Sapphire HD4870 - HP w2207.
Mulettino: A64 3000+ (Zalman 9500) - K8nf4g-sataII - ddr400 2x1gb Vdata
VdW è offline   Rispondi citando il messaggio o parte di esso
Old 06-04-2008, 02:45   #144
VdW
Senior Member
 
L'Avatar di VdW
 
Iscritto dal: Jun 2004
Messaggi: 2171
doppio post
__________________
Se dio avesse voluto che credessimo in lui sarebbe esistito.
Principale: Q6600 (Zalman 9500) - 4core1600twins-sataII - ddr800 2x2gb - Sapphire HD4870 - HP w2207.
Mulettino: A64 3000+ (Zalman 9500) - K8nf4g-sataII - ddr400 2x1gb Vdata
VdW è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 00:01   #145
cubo23
Junior Member
 
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
secondo voi è tutto a posto......
http://www.fileup.itadib.com/downloa...tzKQ3wPGAnQw2F
cubo23 è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 00:51   #146
Chill-Out
Moderatore
 
L'Avatar di Chill-Out
 
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
Quote:
Originariamente inviato da cubo23 Guarda i messaggi
Ciao cubo23 nel tuo log c'è qualcosa di strano, ovvero:

Quote:
C:\Programmi\Internet Explorer\IEXPLORE.EXE (*** hidden *** )
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe (*** hidden *** )
sembra che i processi siano iniettati da qualcosa, avrei bisogno di sapere quanti Account oltre all' Account Amministratore ci sono su questo PC, inoltre con quale Account eri loggato quando hai prodotto il log

Ti suggerisco di seguire la Guida alla disinfezione allegando i log prodotti in un'unico post secondo le sottoindicate modalità, grazie per la collaborazione


MODALITA' DI PUBBLICAZIONE DEI LOG RICHIESTI:

Ogni singolo log, esclusivamente in formato txt, deve essere hostato su MediaFire, pubblicando, nella discussione, singolarmente, per ogni log, il link che verrà rilasciato per il download

Dopo aver prodotto i log apri una nuova discussione qui: http://www.hwupgrade.it/forum/forumdisplay.php?f=125

Ciao
__________________
Try again and you will be luckier.
Chill-Out è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 16:46   #147
cubo23
Junior Member
 
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
Quote:
C:\Programmi\Internet Explorer\IEXPLORE.EXE (*** hidden *** )
C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe (*** hidden *** )
sembra che i processi siano iniettati da qualcosa, avrei bisogno di sapere quanti Account oltre all' Account Amministratore ci sono su questo PC, inoltre con quale Account eri loggato quando hai prodotto il log
ho un solo account e naturalmente la scansione l'ho fatta come amministratore
cubo23 è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 17:05   #148
Chill-Out
Moderatore
 
L'Avatar di Chill-Out
 
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
Quote:
Originariamente inviato da cubo23 Guarda i messaggi
ho un solo account e naturalmente la scansione l'ho fatta come amministratore
Segui la Guida che ti ho linkato, ma il log di Gmer l'hai fatto per controllo oppure riscontri problemi?
__________________
Try again and you will be luckier.
Chill-Out è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 17:15   #149
cubo23
Junior Member
 
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
per controllo
cubo23 è offline   Rispondi citando il messaggio o parte di esso
Old 15-04-2008, 17:23   #150
Chill-Out
Moderatore
 
L'Avatar di Chill-Out
 
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
Quote:
Originariamente inviato da cubo23 Guarda i messaggi
per controllo
Io un controllo con i tool indicati in Guida lo farei
__________________
Try again and you will be luckier.
Chill-Out è offline   Rispondi citando il messaggio o parte di esso
Old 16-04-2008, 02:22   #151
psiconauta
Member
 
L'Avatar di psiconauta
 
Iscritto dal: Apr 2008
Messaggi: 104
re

Quote:
Originariamente inviato da FOXYLADY Guarda i messaggi
Piace molto anche a me l'idea di un thread in cui si parla di gmer, soprattutto se diventa un luogo in cui, magari le persone più esperte (vedi eraser, lucas, breakdown), dessero qualche dritta sull'interpretazione dei log stessi.
Mi piace di meno l'idea di invitare tutti gli utenti a postare qui i loro log, nel senso che (mi spiego meglio).
Se un utente che è infetto apre un thread nella sezione Aiuto sono infetto e posta li, nel suo thread i log di hijackthis e di gmer lo trovo più corretto, perchè già adesso è un pò un casino dire all'utente di postare nel 3d ufficiale i log di hijackthis, diventerebbe un casino ancora più assurdo, dire all'utente che ha il problema di postare il log di hijackthis da una parte e quello di gmer da un'altra,
e poi navigare in 3 thread differenti per dargli una risposta....
Quoto certa-Mente
e unisco alla lista anche HIJACKFREE della stessa "casa" di hijackthis..
per alcuni versi simile a Gmer.
esiste un thread ufficiale di HiJackFree ?
psiconauta è offline   Rispondi citando il messaggio o parte di esso
Old 17-04-2008, 00:23   #152
Andrea9907
Senior Member
 
L'Avatar di Andrea9907
 
Iscritto dal: Dec 2007
Città: prov. RA
Messaggi: 568
Volevo chiedervi 2-3 cose:
La scansione di Gmer non mi ha rilevato rootkit mentre quella di rootkit revealer ne ha rilevate 4 (lui le chiama discrepanze, scritto in inglese ovviamente); immagino siano rootkit, vero?

Un'altra cosa: vi risulta che nella schermata di gmer i pulsanti Scan, Copy e Save anzichè essere in basso a destra siano poco sopra, finendo per coprire il rettangolino dove dentro si trova casella di spunta con a fianco "C:\"? Nella versione precedente non succedeva; ho provato a riscaricarlo ma non è cambiato niente. Boh!
__________________
Andrea
Andrea9907 è offline   Rispondi citando il messaggio o parte di esso
Old 03-07-2008, 14:35   #153
zairon
Junior Member
 
Iscritto dal: Jul 2008
Messaggi: 9
mi leggereste questo log? grazie anticipatamente

Codice:
                                                          GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-03 03:39:27
Windows 6.0.6001 Service Pack 1


---- User code sections - GMER 1.0.14 ----

.text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3756] kernel32.dll!SetUnhandledExceptionFilter  762D6E2D 5 Bytes  JMP 0056DBBD C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)

---- Devices - GMER 1.0.14 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                            fltmgr.sys (Gestione filtri file system Microsoft/Microsoft Corporation)

---- EOF - GMER 1.0.14 ----
          GMER 1.0.14.14536 - http://www.gmer.net
Autostart scan 2008-07-03 03:40:53
Windows 6.0.6001 Service Pack 1


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * lsdelete /*file not found*/

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\Windows\system32\userinit.exe, = C:\Windows\system32\userinit.exe,
@Shellexplorer.exe = explorer.exe
@GinaDLLvrlogon.dll = vrlogon.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
igfxcui@DLLName = igfxdev.dll
psfus@DLLName = C:\Windows\system32\psqlpwd.dll
VESWinlogon@DLLName = VESWinlogon.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs =   

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
a2free@ = "C:\Program Files\a-squared Free\a2service.exe"
aawservice@ = "C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe"
AeLookupSvc@ = %systemroot%\system32\svchost.exe -k netsvcs
AntiVirScheduler@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"
AntiVirService@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"
AudioEndpointBuilder@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
Audiosrv@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
BFE@ = %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
BITS@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Browser@ = %SystemRoot%\System32\svchost.exe -k netsvcs
CLTNetCnService@ = "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon /*file not found*/
CryptSvc@ = %SystemRoot%\system32\svchost.exe -k NetworkService
DcomLaunch@ = %SystemRoot%\system32\svchost.exe -k DcomLaunch
Dhcp@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
Dnscache@ = %SystemRoot%\system32\svchost.exe -k NetworkService
DPS@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
EMDMgmt@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
Eventlog@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
EventSystem@ = %SystemRoot%\system32\svchost.exe -k LocalService
FDResPub@ = %SystemRoot%\system32\svchost.exe -k LocalService
gpsvc@ = %windir%\system32\svchost.exe -k GPSvcGroup
IKEEXT@ = %systemroot%\system32\svchost.exe -k netsvcs
iphlpsvc@ = %SystemRoot%\System32\svchost.exe -k NetSvcs
KtmRm@ = %SystemRoot%\System32\svchost.exe -k NetworkService
LanmanServer@ = %SystemRoot%\system32\svchost.exe -k netsvcs
LanmanWorkstation@ = %SystemRoot%\System32\svchost.exe -k LocalService
lmhosts@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
MMCSS@ = %SystemRoot%\system32\svchost.exe -k netsvcs
MpsSvc@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
netprofm@ = %SystemRoot%\System32\svchost.exe -k LocalService
NlaSvc@ = %SystemRoot%\System32\svchost.exe -k NetworkService
NMSAccessU@ = C:\Program Files\CDBurnerXP\NMSAccessU.exe
nsi@ = %systemroot%\system32\svchost.exe -k LocalService
PcaSvc@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
PLFlash DeviceIoControl Service@ = C:\Windows\system32\IoctlSvc.exe /*file not found*/
PlugPlay@ = %SystemRoot%\system32\svchost.exe -k DcomLaunch
PolicyAgent@ = %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
ProfSvc@ = %systemroot%\system32\svchost.exe -k netsvcs
RapiMgr@ = %SystemRoot%\system32\svchost.exe -k WindowsMobile
RpcSs@ = %SystemRoot%\system32\svchost.exe -k rpcss
SamSs@ = %SystemRoot%\system32\lsass.exe
Schedule@ = %systemroot%\system32\svchost.exe -k netsvcs
seclogon@ = %windir%\system32\svchost.exe -k netsvcs
SENS@ = %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ShellHWDetection@ = %SystemRoot%\System32\svchost.exe -k netsvcs
slsvc@ = %SystemRoot%\system32\SLsvc.exe
Spooler@ = %SystemRoot%\System32\spoolsv.exe
stisvc@ = %SystemRoot%\system32\svchost.exe -k imgsvc
SysMain@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
TabletInputService@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
TBS@ = %SystemRoot%\System32\svchost.exe -k LocalService
Themes@ = %SystemRoot%\System32\svchost.exe -k netsvcs
TOSHIBA Bluetooth Service@ = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
TrkWks@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
upnphost@ = %SystemRoot%\system32\svchost.exe -k LocalService
UxSms@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
VAIO Event Service@ = C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
VzCdbSvc@ = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"
VzFw@ = C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
W32Time@ = %SystemRoot%\system32\svchost.exe -k LocalService
WcesComm@ = %SystemRoot%\system32\svchost.exe -k WindowsMobile
WebClient@ = %SystemRoot%\system32\svchost.exe -k LocalService
WerSvc@ = %SystemRoot%\System32\svchost.exe -k WerSvcGroup
WinDefend@ = %SystemRoot%\System32\svchost.exe -k secsvcs
Winmgmt@ = %systemroot%\system32\svchost.exe -k netsvcs
Wlansvc@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
WPDBusEnum@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
wscsvc@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
wuauserv@ = %systemroot%\system32\svchost.exe -k netsvcs
wudfsvc@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
XAudioService@ = %SystemRoot%\system32\DRIVERS\xaudio.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ApointC:\Program Files\Apoint\Apoint.exe = C:\Program Files\Apoint\Apoint.exe
@DRCU"C:\Program Files\Sony\DRCU\DRCU.exe" = "C:\Program Files\Sony\DRCU\DRCU.exe"
@ISBMgr.exe"C:\Program Files\Sony\ISB Utility\ISBMgr.exe" = "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
@PSQLLauncher"C:\Program Files\Protector Suite QL\launcher.exe" /startup = "C:\Program Files\Protector Suite QL\launcher.exe" /startup
@Windows Mobile-based device management%windir%\WindowsMobile\wmdSync.exe = %windir%\WindowsMobile\wmdSync.exe
@NvCplDaemonRUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
@NvMediaCenterRUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
@avgnt"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
@SunJavaUpdateSched"C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" = "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
@NBKeyScan"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" /*file not found*/ = "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" /*file not found*/
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce >>>
@COMODO Firewall Pro"C:\Program Files\COMODO\Firewall\cfpconfg.exe" -z -o /*file not found*/ = "C:\Program Files\COMODO\Firewall\cfpconfg.exe" -z -o /*file not found*/
@AskSBar Uninstallrundll32 C:\PROGRA~1\UNINST~1.DLL,O -3 = rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3

HKCU\Software\Microsoft\Windows\CurrentVersion\Run@Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun /*file not found*/

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WebCheck = C:\Windows\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler@{8C7461EF-2B13-11d2-BE35-3078302C2030} = %SystemRoot%\system32\browseui.dll

HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L

HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L

HKLM\Software\Classes\ >>>
.exe@ = "%1" %*
.com@ = "%1" %*
.cmd@ = "%1" %*
.bat@ = "%1" %*
.pif@ = "%1" %*
.scr@ = "%1" /S
.hta@ = C:\Windows\system32\mshta.exe "%1" %*

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/%CommonProgramFiles%\System\Ole DB\oledb32.dll /*file not found*/ = %CommonProgramFiles%\System\Ole DB\oledb32.dll /*file not found*/
@{F02C1A0D-BE21-4350-88B0-7367FC96EF3C} /*Computers and Devices*/%systemroot%\system32\NetworkExplorer.dll = %systemroot%\system32\NetworkExplorer.dll
@{E7DE9B1A-7533-4556-9484-B26FB486475E} /**/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{7A80E4A8-8005-11D2-BCF8-00C04F72C717} /*MMC Icon Handler*/%SystemRoot%\system32\mmcshext.dll = %SystemRoot%\system32\mmcshext.dll
@{08165EA0-E946-11CF-9C87-00AA005127ED} /*WebCheckWebCrawler*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7D559C10-9FE9-11d0-93F7-00AA0059CE02} /*Code Download Agent*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} /*WebCheck SyncMgr Handler*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} /*Subscription Mgr*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{F5175861-2688-11d0-9C5E-00AA00A45957} /*Subscription Folder*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7007ACC7-3202-11D1-AAD2-00805FC1270E} /*Network Connections*/%SystemRoot%\System32\netshell.dll = %SystemRoot%\System32\netshell.dll
@{992CFFA0-F557-101A-88EC-00DD010CCC48} /*Network Connections*/%SystemRoot%\System32\netshell.dll = %SystemRoot%\System32\netshell.dll
@{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486} /*IGD Property Sheet Handler*/%SystemRoot%\System32\icsigd.dll = %SystemRoot%\System32\icsigd.dll
@{92dbad9f-5025-49b0-9078-2d78f935e341} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{b9815375-5d7f-4ce2-9245-c9d4da436930} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{f8b8412b-dea3-4130-b36c-5e8be73106ac} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{5FA29220-36A1-40f9-89C6-F4B384B7642E} /*Shell Message Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{8856f961-340a-11d0-a96b-00c04fd705a2} /*Microsoft Web Browser*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3050f3d9-98b5-11cf-bb82-00aa00bdce0b} /*MSHTML Document*/C:\Windows\system32\mshtml.dll = C:\Windows\system32\mshtml.dll
@{25336920-03f9-11cf-8fd0-00aa00686f13} /*HTML Document*/C:\Windows\system32\mshtml.dll = C:\Windows\system32\mshtml.dll
@{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} /*Mail Service*/%SystemRoot%\System32\sendmail.dll = %SystemRoot%\System32\sendmail.dll
@{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} /*Desktop Shortcut*/%SystemRoot%\System32\sendmail.dll = %SystemRoot%\System32\sendmail.dll
@{CC6EEFFB-43F6-46c5-9619-51D571967F7D} /*Web Publishing Wizard*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{add36aa8-751a-4579-a266-d66f5202ccbb} /*Print Ordering via the Web*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{6b33163c-76a5-4b6c-bf21-45de9cd503a1} /*Shell Publishing Wizard Object*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{176d6597-26d3-11d1-b350-080036a75b03} /*ICM Scanner Management*/%SystemRoot%\System32\colorui.dll = %SystemRoot%\System32\colorui.dll
@{5DB2625A-54DF-11D0-B6C4-0800091AA605} /*ICM Monitor Management*/%SystemRoot%\System32\colorui.dll = %SystemRoot%\System32\colorui.dll
@{675F097E-4C4D-11D0-B6C1-0800091AA605} /*ICM Printer Management*/%SystemRoot%\system32\colorui.dll = %SystemRoot%\system32\colorui.dll
@{DBCE2480-C732-101B-BE72-BA78E9AD5B27} /*ICC Profile*/%SystemRoot%\system32\colorui.dll = %SystemRoot%\system32\colorui.dll
@{b2c761c6-29bc-4f19-9251-e6195265baf1} /*Color Control Panel Applet*/(null) = 
@{0D45D530-764B-11d0-A1CA-00AA00C16E65} /*Directory Property UI*/%systemroot%\system32\dsuiext.dll = %systemroot%\system32\dsuiext.dll
@{62AE1F9A-126A-11D0-A14B-0800361B1103} /*Directory Context Menu Verbs*/%systemroot%\system32\dsuiext.dll = %systemroot%\system32\dsuiext.dll
@{8A23E65E-31C2-11d0-891C-00A024AB2DBB} /*Directory Query UI*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} /*Shell properties for a DS object*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} /*Directory Object Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F020E586-5264-11d1-A532-0000F8757D7E} /*Directory Start/Search Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} /*Printers Security Page*/rshx32.dll = rshx32.dll
@{1F2E5C40-9550-11CE-99D2-00AA006E086C} /*NTFS Security Page*/rshx32.dll = rshx32.dll
@{40dd6e20-7c17-11ce-a804-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{77597368-7b15-11d0-a0c2-080036af3f03} /*Web Printer Shell Extension*/%systemroot%\system32\printui.dll = %systemroot%\system32\printui.dll
@{4E40F770-369C-11d0-8922-00A024AB2DBB} /*DS Security Page*/dssec.dll = dssec.dll
@{41E300E0-78B6-11ce-849B-444553540000} /*PlusPack CPL Extension*/%SystemRoot%\system32\themeui.dll = %SystemRoot%\system32\themeui.dll
@{36eef7db-88ad-4e81-ad49-0e313f0c35f8} /*Windows Update*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{74246bfc-4c96-11d0-abef-0020af6b0b7a} /*Device Manager*/%SystemRoot%\System32\devmgr.dll = %SystemRoot%\System32\devmgr.dll
@{7A979262-40CE-46ff-AEEE-7884AC3B6136} /*Add New Hardware*/(null) = 
@{7b81be6a-ce2b-4676-a29e-eb907a5126c5} /*Programs and Features*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{15eae92e-f17a-4431-9f28-805e482dafd4} /*Install New Programs*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd} /*Installed Updates*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{ceefea1b-3e29-4ef1-b34c-fec79c4f70af} /*New Shortcut Wizard*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{0BFCF7B7-E7B6-433a-B205-2904FCF040DD} /*New Shortcut Wizard Modal*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{CFCCC7A0-A282-11D1-9082-006008059382} /*Darwin App Publisher*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{3e7efb4c-faf1-453d-89eb-56026875ef90} /*Get Programs Online*/(null) = 
@{59099400-57FF-11CE-BD94-0020AF85B590} /*Disk Copy Extension*/diskcopy.dll = diskcopy.dll
@{ECF03A32-103D-11d2-854D-006008059367} /*MyDocs Drop Target*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{4a7ded0a-ad25-11d0-98a8-0800361b1103} /*MyFolder Properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{44f3dab6-4392-4186-bb7b-6282ccb7a9f6} /*MyDocuments menu and properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{0DF44EAA-FF21-4412-828E-260A8728E7F1} /*Taskbar and Start Menu*/(null) = 
@{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} /*Search*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} /*Run...*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} /*Internet*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} /*E-mail*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0} /*Start Menu OEM Command*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} /*Set Program Access and Defaults*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3080F90D-D7AD-11D9-BD98-0000947B0257} /*Show Desktop*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3080F90E-D7AD-11D9-BD98-0000947B0257} /*Window Switcher*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{eb124705-128b-40d4-8dd8-d93ed12589a4} /*WPL property store*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3c2654c6-7372-4f6b-b310-55d6128f49d2} /*Alphabetical Categorizer*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{9DBD2C50-62AD-11d0-B806-00C04FD706EC} /*Summary Info Thumbnail handler (DOCFILES)*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{708e1662-b832-42a8-bbe1-0a77121e3908} /*Tree property value folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{71f96385-ddd6-48d3-a0c1-ae06e8b055fb} /*Explorer Browser*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{b2952b16-0e07-4e5a-b993-58c52cb94cae} /*Search Folders*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{437ff9c0-a07f-4fa0-af80-84b6c6440a16} /*Command Folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{90f8c90b-04e0-4e92-a186-e6e9c125d664} /*Property Labels*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{1b24a030-9b20-49bc-97ac-1be4426f9e59} /*ActiveDirectory Folder*/(null) = 
@{34449847-FD14-4fc8-A75A-7432F5181EFB} /*ActiveDirectory Folder*/(null) = 
@{C8494E42-ACDD-4739-B0FB-217361E4894F} /*Sam Account Folder*/(null) = 
@{E29F9716-5C08-4FCD-955A-119FDB5A522D} /*Sam Account Folder*/(null) = 
@{D20EA4E1-3957-11d2-A40B-0C5020524152} /*Fonts*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524153} /*Administrative Tools*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{b155bdf8-02f0-451e-9a26-ae317cfd7779} /*nethood delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{DFFACDC5-679F-4156-8947-C5C76BC0B67F} /*users files delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{ed50fc29-b964-48a9-afb3-15ebb9b97f36} /*printhood delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{328B0346-7EAF-4BBE-A479-7CB88A095F5B} /*Layout Folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} /*Control Panel command object for Start menu*/(null) = 
@{E44E5D18-0652-4508-A4E2-8A090067BCB0} /*Default Programs command object for Start menu*/(null) = 
@{4336a54d-038b-4685-ab02-99bb52d3fb8b} /*Public Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{00021401-0000-0000-C000-000000000046} /*Shortcut*/shell32.dll = shell32.dll
@{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9} /*Search Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B} /*.fon, .otf, .ttc or .ttf files*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{66742402-F9B9-11D1-A202-0000F81FEDEE} /*.cpl, .dll, .exe, .ocx, .rll or .sys files*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{D34A6CA6-62C2-4C34-8A7C-14709C1AD938} /*Common Places Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{865e5e76-ad83-4dca-a109-50dc2113ce9a} /*Programs Folder and Fast Items*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{21ec2020-3aea-1069-a2dd-08002b30309d} /*Control Panel*/shell32.dll = shell32.dll
@{25585dc7-4da0-438d-ad04-e42c8d2d64b9} /*Client application shell extension*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{6dfd7c5c-2451-11d3-a299-00c04f8ef6af} /*Folder Options*/(null) = 
@{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3} /*Microsoft Windows RTF Preview Handler*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{1531d583-8375-4d3f-b5fb-d23bbd169f22} /*Window TXT Preview Handler*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{97e467b4-98c6-4f19-9588-161b7773d6f6} /*Office Document Property Handler*/%SystemRoot%\system32\propsys.dll = %SystemRoot%\system32\propsys.dll
@{88C6C381-2E85-11D0-94DE-444553540000} /*ActiveX Cache Folder*/C:\Windows\system32\occache.dll = C:\Windows\system32\occache.dll
@{5E6AB780-7743-11CF-A12B-00AA004AE837} /*Microsoft Internet Toolbar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7BA4C742-9E81-11CF-99D3-00AA004AE837} /*Microsoft BrowserBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{056440FD-8568-48e7-A632-72157243B55B} /*Explorer Navigation Bar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980} /*Explorer Travel Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F} /*Explorer Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{2C2577C2-63A7-40e3-9B7F-586602617ECB} /*Explorer Query Band*/(null) = 
@{21569614-B795-46b1-85F4-E737A8DC09AD} /*Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{169A0691-8DF9-11d1-A1C4-00C04FD75D13} /*In-pane search*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{AF4F6510-F982-11d0-8595-00AA004CD6D8} /*Registry Tree Options Utility*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{01E04581-4EEE-11d0-BFE9-00AA005B4383} /*&Address*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{a542e116-8088-4146-a352-b0d06e7f6af6} /*Address EditBox*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{F61FFEC1-754F-11d0-80CA-00AA005B4383} /*BandProxy*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2763-6A77-11D0-A535-00C04FD7D062} /*Microsoft AutoComplete*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{596742A5-1393-4e13-8765-AE1DF71ACAFB} /*Microsoft Breadcrumb Bar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6756A641-DE71-11d0-831B-00AA005B4383} /*MRU AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} /*Custom MRU AutoCompleted List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2764-6A77-11D0-A535-00C04FD7D062} /*Microsoft History AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{03C036F1-A186-11D0-824A-00AA005B4383} /*Microsoft Shell Folder AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2765-6A77-11D0-A535-00C04FD7D062} /*Microsoft Multiple AutoComplete List Container*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4E-521C-11D0-B792-00A0C90312E1} /*Shell Band Site Menu*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} /*Shell DeskBarApp*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4D-521C-11D0-B792-00A0C90312E1} /*Shell Rebar BandSite*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DD313E04-FEFF-11d1-8ECD-0000F87A470C} /*User Assist*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} /*Global Folder Settings*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} /*Search Control*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{4d5c8c2a-d075-11d0-b416-00c04fb90376} /*Microsoft CommBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} /*File Open Dialog*/%SystemRoot%\System32\comdlg32.dll = %SystemRoot%\System32\comdlg32.dll
@{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B} /*File Save Dialog*/%SystemRoot%\System32\comdlg32.dll = %SystemRoot%\System32\comdlg32.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\Windows\system32\dfshim.dll = C:\Windows\system32\dfshim.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\Windows\system32\dfshim.dll = C:\Windows\system32\dfshim.dll
@{92337A8C-E11D-11D0-BE48-00C04FC30DF6} /*OlePrn.PrinterURL*/%SystemRoot%\system32\oleprn.dll = %SystemRoot%\system32\oleprn.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft XPS Properties*/%SystemRoot%\system32\XPSSHHDR.DLL = %SystemRoot%\system32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft XPS Thumbnail*/%SystemRoot%\system32\XPSSHHDR.DLL = %SystemRoot%\system32\XPSSHHDR.DLL
@{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b} /*View Available Networks*/(null) = 
@{13D3C4B8-B179-4ebb-BF62-F704173E7448} /*Windows Contact Preview Handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{32714800-2E5F-11d0-8B85-00AA0044F941} /*For &People...*/%ProgramFiles%\Windows Mail\wabfind.dll /*file not found*/ = %ProgramFiles%\Windows Mail\wabfind.dll /*file not found*/
@{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} /*Contacts folder*/(null) = 
@{4F58F63F-244B-4c07-B29F-210BE59BE9B4} /*.group shell extension handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{8082C5E6-4C27-48ec-A809-B8E1122E8F97} /*.contact shell extension handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{16C2C29D-0E5F-45f3-A445-03E03F587B7D} /*group_wab_auto_file*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{CF67796C-F57F-45F8-92FB-AD698826C602} /*contact_wab_auto_file*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{7444C717-39BF-11D1-8CD9-00C04FC29D45} /*Crypto PKO Extension*/%SystemRoot%\system32\cryptext.dll = %SystemRoot%\system32\cryptext.dll
@{7444C719-39BF-11D1-8CD9-00C04FC29D45} /*Crypto Sign Extension*/%SystemRoot%\system32\cryptext.dll = %SystemRoot%\system32\cryptext.dll
@{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} /*Compatibility Property Page*/%windir%\system32\acppage.dll = %windir%\system32\acppage.dll
@{F0152790-D56E-4445-850E-4F3117DB740C} /*Remote Sessions CPL Extension*/%SystemRoot%\system32\remotepg.dll = %SystemRoot%\system32\remotepg.dll
@{4026492f-2f69-46b8-b9bf-5654fc07e423} /*Windows Firewall*/(null) = 
@{D555645E-D4F8-4c29-A827-D93C859C4F2A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\Windows\system32\extmgr.dll = C:\Windows\system32\extmgr.dll
@{60254CA5-953B-11CF-8C96-00AA00B8708C} /*Shell extensions for Windows Script Host*/C:\Windows\system32\wshext.dll = C:\Windows\system32\wshext.dll
@{fcfeecae-ee1b-4849-ae50-685dcf7717ec} /*Problem Reports and Solutions*/(null) = 
@{a304259d-52b8-4526-8b1a-a1d6cecc8243} /*iSCSI Initiator*/(null) = 
@{8E908FC9-BECC-40f6-915B-F4CA0E70D03D} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{143A62C8-C33B-11D1-84FE-00C04FA34A14} /*Microsoft Agent Character Property Sheet Handler*/%SystemRoot%\MSAgent\agentpsh.dll = %SystemRoot%\MSAgent\agentpsh.dll
@{025A5937-A6BE-4686-A844-36FE4BEC8B6D} /*Microsoft Power Options*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{BB06C0E4-D293-4f75-8A90-CB05B6477EEE} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{17cd9488-1228-4b2f-88ce-4298e93e0966} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{60632754-c523-4b62-b45c-4172da012619} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9C60DE1E-E5FC-40f4-A487-460851A8D915} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{42071712-76d4-11d1-8b24-00a0c9068ff3} /*Display Adapter CPL Extension*/deskadp.dll = deskadp.dll
@{42071713-76d4-11d1-8b24-00a0c9068ff3} /*Display Monitor CPL Extension*/deskmon.dll = deskmon.dll
@{f92e8c40-3d33-11d2-b1aa-080036a75b03} /*Display TroubleShoot CPL Extension*/deskperf.dll = deskperf.dll
@{3EA48300-8CF6-101B-84FB-666CCB9BCD32} /*OLE Docfile Property Page*/docprop.dll = docprop.dll
@{11dbb47c-a525-400b-9e80-a54615a090c0} /*Execute Folder*/ExplorerFrame.dll = ExplorerFrame.dll
@{90b9bce2-b6db-4fd3-8451-35917ea1081b} /*Search Execute Command*/ExplorerFrame.dll = ExplorerFrame.dll
@{7988B573-EC89-11cf-9C00-00AA00A14F56} /*Disk Quota UI*/dskquoui.dll = dskquoui.dll
@{BD84B380-8CA2-1069-AB1D-08000948F534} /*Microsoft Windows Font Folder*/%SystemRoot%\system32\fontext.dll = %SystemRoot%\system32\fontext.dll
@{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E} /*Microsoft Windows Font File Icon Handler*/fontext.dll = fontext.dll
@{1a184871-359e-4f67-aad9-5b9905d62232} /*Microsoft Windows Font File Context Menu Handler*/fontext.dll = fontext.dll
@{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01} /*Microsoft Windows Font Previewer*/fontext.dll = fontext.dll
@{63da6ec0-2e98-11cf-8d82-444553540000} /*FTP Folders Webview*/%SystemRoot%\system32\msieftp.dll = %SystemRoot%\system32\msieftp.dll
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Compressed (zipped) Folder*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af} /*Compressed (zipped) Folder Context Menu*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{ed9d80b9-d157-457b-9192-0e7280313bf0} /*Compressed (zipped) Folder Drop Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{911051fa-c21c-4246-b470-070cd8df6dc4} /*.cab or .zip files*/(null) = 
@{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} /*.CAB file viewer*/cabview.dll = cabview.dll
@{59be4990-f85c-11ce-aff7-00aa003ca9f6} /*Shell extensions for Microsoft Windows Network objects*/ntlanui2.dll = ntlanui2.dll
@{da67b8ad-e81b-4c70-9b91b417b5e33527} /*Windows Search Shell Service*/(null) = 
@{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} /*DfsShell.DfsShell Property Sheet*/DfsShlEx.dll = DfsShlEx.dll
@{a38b883c-1682-497e-97b0-0a3a9e801682} /*IPropertyStore Handler for Images*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{C7657C4A-9F68-40fa-A4DF-96BC08EB3551} /*Photo Thumbnail Provider*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{3F30C968-480A-4C6C-862D-EFC0897BB84B} /*Photo Thumbnail Extractor*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{BC65FB43-1958-4349-971A-210290480130} /*Network Explorer Property Sheet Handler*/%SystemRoot%\System32\NcdProp.dll = %SystemRoot%\System32\NcdProp.dll
@{d3e34b21-9d75-101a-8c3d-00aa001a1652} /*Bitmap Image*/(null) = 
@{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} /*Video Media Properties Handler*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{E598560B-28D5-46aa-A14A-8A3BEA34B576} /*Windows Photo Gallery Viewer Video Verbs*/%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/
@{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3} /*Microsoft.ScannersAndCameras*/(null) = 
@{0a4286ea-e355-44fb-8086-af3df7645bd9} /*Windows Media Player*/C:\PROGRA~1\WI4EB4~1\wmpband.dll = C:\PROGRA~1\WI4EB4~1\wmpband.dll
@{BB6B2374-3D79-41DB-87F4-896C91846510} /*EMDFileProperties*/emdmgmt.dll = emdmgmt.dll
@{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} /*Audio Media Properties Handler*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{E95A4861-D57A-4be1-AD0F-35267E261739} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{89D83576-6BD1-4c86-9454-BEB04E94C819} /*MAPI Search Namespace Extension*/%systemroot%\system32\mssvp.dll = %systemroot%\system32\mssvp.dll
@{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} /*Offline Files Folder*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{7A0F6AB7-ED84-46B6-B47E-02AA159A152B} /*Sync Center Simple Conflict Presenter*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{9D687A4C-1404-41ef-A089-883B6FBECDE6} /*Windows Photo Gallery Viewer Autoplay Handler*/(null) = 
@{BE122A0E-4503-11DA-8BDE-F66BAD1E3F3A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{60fd46de-f830-4894-a628-6fa81bc0190d} /*DropTarget Object for Photo Printing Wizard*/%SystemRoot%\system32\photowiz.dll = %SystemRoot%\system32\photowiz.dll
@{37efd44d-ef8d-41b1-940d-96973a50e9e0} /*Windows Sidebar Properties*/(null) = 
@{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\system32\audiodev.dll = %SystemRoot%\system32\audiodev.dll
@{00f20eb5-8fd6-4d9d-b75e-36801766c8f1} /*PhotoAcqDropTarget*/%ProgramFiles%\Windows Photo Gallery\PhotoAcq.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoAcq.dll /*file not found*/
@{BC48B32F-5910-47F5-8570-5074A8A5636A} /*Sync Results Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{ED228FDF-9EA8-4870-83B1-96B02CFE0D52} /*Games Folder*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{4E77131D-3629-431c-9818-C5679DC83E81} /*Offline Files Icon Overlay Handler*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{E413D040-6788-4C22-957E-175D1C513A34} /*Sync Center Conflict Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{67718415-c450-4f3c-bf8a-b487642dc39b} /*Windows Features*/(null) = 
@{335a31dd-f04b-4d76-a925-d6b47cf360df} /**/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{91ADC906-6722-4B05-A12B-471ADDCCE132} /*Touch Band*/%SystemRoot%\System32\TouchX.dll = %SystemRoot%\System32\TouchX.dll
@{7D4734E6-047E-41e2-AEAA-E763B4739DC4} /*Windows Media Player Play as Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{2781761E-28E0-4109-99FE-B9D127C57AFE} /*Windows Defender IOfficeAntiVirus implementation*/%ProgramFiles%\Windows Defender\MpOav.dll /*file not found*/ = %ProgramFiles%\Windows Defender\MpOav.dll /*file not found*/
@{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A} /*Windows Photo Gallery Viewer Image Verbs*/%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/
@{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Play as Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{4B534112-3AF6-4697-A77C-D62CE9B9E7CF} /*Sync Center Event Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C} /*Sync Setup Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} /*Offline Files Context Menu*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{85BBD920-42A0-1069-A2E4-08002B30309D} /*Briefcase*/syncui.dll = syncui.dll
@{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A} /*GameUX.RichGameMediaThumbnail*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{7EFA68C6-086B-43e1-A2D2-55A113531240} /*Offline Files Property Sheet Extension*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{d8559eb9-20c0-410e-beda-7ed416aecc2a} /*Windows Defender*/(null) = 
@{576C9E85-1300-4EF5-BF6B-D00509F4EDCD} /*Sync Center Handler Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{5ea4f148-308c-46d7-98a9-49041b1dd468} /*Mobility Center Control Panel*/(null) = 
@{289978AC-A101-4341-A817-21EBA7FD046D} /*Sync Center Conflict Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{877ca5ac-cb41-4842-9c69-9136e42d47e2} /*File Backup Index*/%systemroot%\system32\sdshext.dll = %systemroot%\system32\sdshext.dll
@{71D99464-3B6B-475C-B241-E15883207529} /*Sync Results Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{10CFC467-4392-11d2-8DB4-00C04FA31A66} /*Offline Files Folder Options*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{B32D3949-ED98-4DBB-B347-17A144969BBA} /*Sync Center Item Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Burn Audio CD Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{2E9E59C0-B437-4981-A647-9C34B9B90891} /*Sync Setup Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{58E3C745-D971-4081-9034-86E34B30836A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} /*Sync Center Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1} /*Welcome Center*/oobefldr.dll = oobefldr.dll
@{15D633E2-AD00-465b-9EC7-F56B7CDF8E27} /*Tablet PC Input Panel*/%CommonProgramFiles%\microsoft shared\ink\TipBand.dll /*file not found*/ = %CommonProgramFiles%\microsoft shared\ink\TipBand.dll /*file not found*/
@{78F3955E-3B90-4184-BD14-5397C15F1EFC} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{F04CC277-03A2-4277-96A9-77967471BDFF} /*Sync Center Conflict Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{53BEDF0B-4E5B-4183-8DC9-B844344FA104} /*Microsoft Windows MAPI Preview Handler*/%SystemRoot%\system32\mssvp.dll = %SystemRoot%\system32\mssvp.dll
@{6b9228da-9c15-419e-856c-19e768a13bdc} /*Windows gadget DropTarget*/%ProgramFiles%\Windows Sidebar\sbdrop.dll /*file not found*/ = %ProgramFiles%\Windows Sidebar\sbdrop.dll /*file not found*/
@{8E25992B-373E-486E-80E5-BD23AE417E66} /*Sync Center Device Notification Sink*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{031EE060-67BC-460d-8847-E4A7C5E45A27} /*Windows Media Player Rich Preview Handler*/(null) = 
@{1FA9085F-25A2-489B-85D4-86326EEDCD87} /*Manage Wireless Networks*/%SystemRoot%\system32\wlanpref.dll = %SystemRoot%\system32\wlanpref.dll
@{7dda204b-2097-47c9-8323-c40bb840ae44} /*XPS document*/(null) = 
@{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60} /*RichGameMediaPropertyStore Class*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{BD7A2E7B-21CB-41b2-A086-B309680C6B7E} /*Client Side Cache Namespace Extension*/%systemroot%\system32\mssvp.dll = %systemroot%\system32\mssvp.dll
@{8A734961-C4AA-4741-AC1E-791ACEBF5B39} /*Windows Media Player Shop Music Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{7A9D77BD-5403-11d2-8785-2E0420524153} /*User Accounts*/(null) = 
@{c5a40261-cd64-4ccf-84cb-c394da41d590} /*Video Thumbnail Extractor*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\Windows\system32\nvcpl.dll = C:\Windows\system32\nvcpl.dll
@{ED58A35B-B554-42AF-A26C-6F3D424200D3} /*Sony Power Management Extensiond*/C:\Program Files\Sony\VAIO Power Management\SPMPanel.dll = C:\Program Files\Sony\VAIO Power Management\SPMPanel.dll
@{9AFDE8D6-200C-4b41-A5FC-B7251DFD1A8E} /*Safearchive ContextMenu Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{055EF591-5C38-49a0-9BDA-51B1D69D0BF4} /*Safearchive ShellFolder Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{66C99756-1C92-4d3e-BA69-9400A6F731F5} /*Safearchive PropertySheetHandler Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{E6D7D89A-2232-446d-8A0F-D0F9B06DB1CA} /*Safearchive ExtractIcon Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL = C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
@{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B} /*Bluetooth*/C:\Windows\system32\TosBtExt.dll = C:\Windows\system32\TosBtExt.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/(null) = 
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/(null) = 
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/(null) = 
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll = C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll
@{0563DB41-F538-4B37-A92D-4659049B7766} /*WLMD Message Handler*/C:\Program Files\Windows Live\Mail\mailcomm.dll = C:\Program Files\Windows Live\Mail\mailcomm.dll
@{06A2568A-CED6-4187-BB20-400B8C02BE5A} /**/(null) = 
@{00F33137-EE26-412F-8D71-F84E4C2C6625} /**/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} /*Windows Live Photo Gallery Autoplay Drop Target*/(null) = 
@{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} /*Windows Live Photo Gallery Viewer Drop Target*/(null) = 
@{00F374B7-B390-4884-B372-2FC349F2172B} /*Windows Live Photo Gallery Editor Drop Target*/(null) = 
@{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} /*Windows Live Photo Gallery Viewer Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} /*Windows Live Photo Gallery Editor Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F30F90-3E96-453B-AFCD-D71989ECC2C7} /*Windows Live Photo Gallery Autoplay Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\Windows\system32\nvcpl.dll = C:\Windows\system32\nvcpl.dll
@{A155339D-CCCD-4714-85EB-3754B804C9DF} /*a-squared Free Shell Extension*/C:\Program Files\a-squared Free\a2freecontmenu.dll = C:\Program Files\a-squared Free\a2freecontmenu.dll
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B} /*Bluetooth*/ = C:\Windows\system32\TosBtExt.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
BriefcaseMenu@{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\shell32.dll
Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
tosBtShllExt@{6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1} = C:\Windows\system32\TosBtShell.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = %SystemRoot%\system32\shell32.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
Offline Files@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} = %SystemRoot%\System32\cscui.dll
Photo! 3D ScreenSaver@{AA7A03E6-7FA5-42E7-9D7A-9A2A4E344B3F} = 
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
tosBtShllExt@{6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1} = C:\Windows\system32\TosBtShell.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{596AB062-B4D2-4215-9F74-E9109B0A8153} = %SystemRoot%\system32\twext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
a-squared Free Shell Extension@{A155339D-CCCD-4714-85EB-3754B804C9DF} = C:\Program Files\a-squared Free\a2freecontmenu.dll
BriefcaseMenu@{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
Offline Files@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} = %SystemRoot%\System32\cscui.dll
Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/ = C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\program files\google\googletoolbar1.dll = c:\program files\google\googletoolbar1.dll
@{CA6319C0-31B7-401E-A518-A07C3DB8F777}C:\PROGRA~1\GOOGLE~1\BAE.dll = C:\PROGRA~1\GOOGLE~1\BAE.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://it.yahoo.com = http://it.yahoo.com
@Start Pagehttp://home.sweetim.com = http://home.sweetim.com
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.comodo.com/search/ = http://www.comodo.com/search/
@Local PageC:\Windows\system32\blank.htm = C:\Windows\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
application/octet-stream@CLSID = mscoree.dll
application/x-complus@CLSID = mscoree.dll
application/x-msdownload@CLSID = mscoree.dll
deflate@CLSID = C:\Windows\system32\urlmon.dll
gzip@CLSID = C:\Windows\system32\urlmon.dll
text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
about@CLSID = C:\Windows\system32\mshtml.dll
cdl@CLSID = C:\Windows\system32\urlmon.dll
dvd@CLSID = C:\Windows\System32\msvidctl.dll
file@CLSID = C:\Windows\system32\urlmon.dll
ftp@CLSID = C:\Windows\system32\urlmon.dll
http@CLSID = C:\Windows\system32\urlmon.dll
https@CLSID = C:\Windows\system32\urlmon.dll
its@CLSID = %SystemRoot%\System32\itss.dll
javascript@CLSID = C:\Windows\system32\mshtml.dll
livecall@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
local@CLSID = C:\Windows\system32\urlmon.dll
mailto@CLSID = C:\Windows\system32\mshtml.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
mk@CLSID = C:\Windows\system32\urlmon.dll
ms-its@CLSID = %SystemRoot%\System32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
res@CLSID = C:\Windows\system32\mshtml.dll
tv@CLSID = C:\Windows\System32\msvidctl.dll
vbscript@CLSID = C:\Windows\system32\mshtml.dll
wlmailhtml@CLSID = C:\Program Files\Windows Live\Mail\mailcomm.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain = 

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6AE2AC5C-D545-44E9-928B-693253A07B39} /*Connessione alla rete locale (LAN)*/ >>>
@IPAddress = 
@NameServer = 
@Domain = 

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
000000000001@LibraryPath = %SystemRoot%\system32\NLAapi.dll
000000000002@LibraryPath = %SystemRoot%\system32\napinsp.dll
000000000003@LibraryPath = %SystemRoot%\system32\pnrpnsp.dll
000000000004@LibraryPath = %SystemRoot%\system32\pnrpnsp.dll
000000000005@LibraryPath = %SystemRoot%\System32\mswsock.dll
000000000006@LibraryPath = %SystemRoot%\System32\winrnr.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000004@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000005@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000018@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000019@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000020@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000021@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000022@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000023@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000024@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000025@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000026@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000027@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000028@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup = Bluetooth Manager.lnk

---- EOF - GMER 1.0.14 ----
zairon è offline   Rispondi citando il messaggio o parte di esso
Old 03-07-2008, 21:21   #154
Nuz
Senior Member
 
L'Avatar di Nuz
 
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
Mi pare che GMER non abbia rilevato infezioni. Attendi comunque il parere di qualcun altro o effettua scansioni antirootkit con altri software ad es. AVIRA Rootkit Detection.

Nuz è offline   Rispondi citando il messaggio o parte di esso
Old 04-07-2008, 00:41   #155
Chill-Out
Moderatore
 
L'Avatar di Chill-Out
 
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
zairon

Il log pare pulito, sarebbe più fruibile se allegato su uno dei seguenti server http://fileqube.com/ o http://www.mediafire.com/index.php

Ciao
__________________
Try again and you will be luckier.
Chill-Out è offline   Rispondi citando il messaggio o parte di esso
Old 04-07-2008, 01:27   #156
zairon
Junior Member
 
Iscritto dal: Jul 2008
Messaggi: 9
scusate

avevo fatto la scanzione da utente, da amministratore gmer sotto la voce rootkit non mi ha trovato niente qui c'è il link dell' autostart , prima avevo fatto anche una scanzione con f secure internet 2008 ma non mi ha trovato niente grazie per la disponibilità e scusate ancora
zairon è offline   Rispondi citando il messaggio o parte di esso
Old 04-07-2008, 01:30   #157
zairon
Junior Member
 
Iscritto dal: Jul 2008
Messaggi: 9
mi ero dimenticato il link

http://www.fileqube.com/shared/ssceABZg52807
zairon è offline   Rispondi citando il messaggio o parte di esso
Old 06-09-2008, 18:22   #158
siope
Junior Member
 
Iscritto dal: Sep 2008
Messaggi: 7
petreste dare un'occhiata a questo log?
nn ci sono voci in rosso ma vorrei un'analisi più sicura..
grazie mille

http://www.fileqube.com/shared/NONut95993
siope è offline   Rispondi citando il messaggio o parte di esso
Old 20-09-2008, 13:21   #159
federico_78
Senior Member
 
L'Avatar di federico_78
 
Iscritto dal: Mar 2006
Messaggi: 608
Ciao a tutti !! Ho un problema con il pc...ogni tanto si blocca, poi riprende a funzionare, poi si blocca, poi riprende...etc, etc!!!
Antivir e Spyware Terminator non mi hanno trovato nulla, A-Squared si blocca prima che finisca la scansione. Ho fatto analizzare log di Hijack ma non ha trovato nulla di rilevante. Stò facendo scansione on-line con F-Secure. Ora vi posto il log di Gmer...

Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-20 12:46:06
Windows 5.1.2600 Service Pack 3


---- User code sections - GMER 1.0.14 ----

.text           C:\WINDOWS\Explorer.EXE[324] ntdll.dll!NtClose                                              7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] ntdll.dll!LdrUnloadDll                                         7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] GDI32.dll!BitBlt                                               77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCA                                            77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCW                                            77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCW + 3                                        77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\Explorer.EXE[324] USER32.dll!EndTask                                             7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] USER32.dll!mouse_event                                         7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] USER32.dll!keybd_event                                         7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] ole32.dll!CoCreateInstanceEx                                   774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\Explorer.EXE[324] ole32.dll!CoGetClassObject                                     774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ntdll.dll!LdrUnloadDll        7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!EndTask            7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!mouse_event        7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!keybd_event        7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!BitBlt              77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCA           77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCW           77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCW + 3       77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ole32.dll!CoCreateInstanceEx  774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ole32.dll!CoGetClassObject    774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\winlogon.exe[984] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\winlogon.exe[984] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtClose                                    7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] ntdll.dll!LdrUnloadDll                               7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] USER32.dll!EndTask                                   7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] USER32.dll!mouse_event                               7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] USER32.dll!keybd_event                               7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] GDI32.dll!BitBlt                                     77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCA                                  77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCW                                  77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCW + 3                              77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\services.exe[1032] ole32.dll!CoCreateInstanceEx                         774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\services.exe[1032] ole32.dll!CoGetClassObject                           774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtClose                                       7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!LdrUnloadDll                                  7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!EndTask                                      7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!mouse_event                                  7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!keybd_event                                  7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!BitBlt                                        77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCA                                     77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCW                                     77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCW + 3                                 77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\lsass.exe[1044] ole32.dll!CoCreateInstanceEx                            774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\lsass.exe[1044] ole32.dll!CoGetClassObject                              774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\svchost.exe[1204] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1204] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\svchost.exe[1268] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1268] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] ntdll.dll!NtClose                           7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] ntdll.dll!LdrUnloadDll                      7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!EndTask                          7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!mouse_event                      7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!keybd_event                      7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!BitBlt                            77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCA                         77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCW                         77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCW + 3                     77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] ole32.dll!CoCreateInstanceEx                774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\Programmi\Windows Defender\MsMpEng.exe[1300] ole32.dll!CoGetClassObject                  774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\svchost.exe[1480] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1480] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\svchost.exe[1508] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1508] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] ntdll.dll!NtClose                                     7C91CFD0 5 Bytes  JMP 10005060 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] ntdll.dll!LdrUnloadDll                                7C92736B 5 Bytes  JMP 10004F90 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!EndTask                                    7E3DA0A5 5 Bytes  JMP 10004C30 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!mouse_event                                7E3E673F 5 Bytes  JMP 100016D0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!keybd_event                                7E3E6783 5 Bytes  JMP 10001550 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!BitBlt                                      77E46F79 5 Bytes  JMP 10001860 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCA                                   77E4B7C2 5 Bytes  JMP 10001230 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCW                                   77E4BE28 2 Bytes  JMP 100013C0 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCW + 3                               77E4BE2B 2 Bytes  [ 1B, 98 ]
.text           C:\WINDOWS\system32\svchost.exe[1632] ole32.dll!CoCreateInstanceEx                          774D0526 5 Bytes  JMP 10004960 C:\WINDOWS\system32\guard32.dll
.text           C:\WINDOWS\system32\svchost.exe[1632] ole32.dll!CoGetClassObject                            774E56C5 5 Bytes  JMP 10004AD0 C:\WINDOWS\system32\guard32.dll

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT             \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter]                         [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter]                          [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol]                   [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol]                     [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol]                    [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter]                         [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter]                        [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol]                  [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol]                    [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol]                      [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter]                           [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter]                          [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol]                     [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol]                   [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter]                         [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter]                          [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter]                           [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter]                            [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol]                       [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol]                     [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol]                   [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter]                         [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter]                          [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO)

---- Devices - GMER 1.0.14 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                      InCDRec.sys (Nero InCD File System Recognizer/Nero AG)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                    cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                   cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                   cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                 cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                    InCDRec.sys (Nero InCD File System Recognizer/Nero AG)

---- Registry - GMER 1.0.14 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0003c935273f                 
Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0003c935273f@001370dd26fa    0x4B 0x43 0x40 0xA9 ...
Reg             HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0003c935273f                     
Reg             HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0003c935273f@001370dd26fa        0x4B 0x43 0x40 0xA9 ...

---- EOF - GMER 1.0.14 ----
federico_78 è offline   Rispondi citando il messaggio o parte di esso
Old 24-09-2008, 18:23   #160
Taxon
Senior Member
 
L'Avatar di Taxon
 
Iscritto dal: Feb 2004
Città: ♪ ♫ un giorno all'improvviso... ♪ ♫
Messaggi: 5716
Ciao amisci, mi date una mnao con il seguente log ???
Grazie anticipatamente

Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-24 18:17:44
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.14 ----

SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwAllocateVirtualMemory [0xB6818960]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwAssignProcessToJobObject [0xB6818D90]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwConnectPort [0xB6818280]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateFile [0xB681A290]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateKey [0xB681AE30]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreatePort [0xB6818140]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateProcess [0xB6818EC0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateProcessEx [0xB6816CD0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateSection [0xB68168D0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwCreateThread [0xB6817280]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwDebugActiveProcess [0xB6817B10]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwDeleteFile [0xB681A8F0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwDeleteKey [0xB6819D10]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwDeleteValueKey [0xB681B6A0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwEnumerateKey [0xB681A270]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwEnumerateValueKey [0xB681A280]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwLoadDriver [0xB68187D0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwLoadKey [0xB681BA10]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwOpenFile [0xB681A650]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwOpenKey [0xB6819EC0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwOpenProcess [0xB6816FE0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwOpenSection [0xB6816B00]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwOpenThread [0xB6817660]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwProtectVirtualMemory [0xB6818AD0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwQueryKey [0xB681A250]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwQueryValueKey [0xB681A260]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwReplaceKey [0xB6819ED0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwRequestWaitReplyPort [0xB68184D0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwRestoreKey [0xB681A090]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwResumeThread [0xB6817EC0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSaveKey [0xB681A240]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSetContextThread [0xB68179C0]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSetInformationFile [0xB681AB50]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSetValueKey [0xB681B190]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwShutdownSystem [0xB6818710]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSuspendProcess [0xB6818000]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSuspendThread [0xB6817D60]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwSystemDebugControl [0xB6817C40]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwTerminateProcess [0xB6817130]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwTerminateThread [0xB6817850]
SSDT            \??\C:\WINDOWS\system32\drivers\OADriver.sys                                                           ZwWriteVirtualMemory [0xB6818C30]

INT 0x62        ?                                                                                                      89B9EBF8
INT 0x63        ?                                                                                                      899E9BF8
INT 0x63        ?                                                                                                      899E9BF8
INT 0x63        ?                                                                                                      899E9BF8
INT 0x83        ?                                                                                                      89B9EBF8
INT 0x83        ?                                                                                                      89B9EBF8
INT 0x83        ?                                                                                                      899E9BF8
INT 0x83        ?                                                                                                      899E9BF8
INT 0x83        ?                                                                                                      89B9EBF8

---- Kernel code sections - GMER 1.0.14 ----

.text           ntkrnlpa.exe!ZwCallbackReturn + 2C7C                                                                   80504508 12 Bytes  [ 40, 81, 81, B6, C0, 8E, 81, ... ]
.text           ntkrnlpa.exe!ZwCallbackReturn + 2FB8                                                                   80504844 12 Bytes  [ 00, 80, 81, B6, 60, 7D, 81, ... ]
?               spcu.sys                                                                                               Impossibile trovare il file specificato. !
.text           USBPORT.SYS!DllUnload                                                                                  B9C908AC 5 Bytes  JMP 899E91D8 
.text           axrb2mo2.SYS                                                                                           B935B386 35 Bytes  [ 00, 00, 00, 00, 00, 00, 20, ... ]
.text           axrb2mo2.SYS                                                                                           B935B3AA 24 Bytes  [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text           axrb2mo2.SYS                                                                                           B935B3C4 3 Bytes  [ 00, 70, 02 ]
.text           axrb2mo2.SYS                                                                                           B935B3C9 1 Byte  [ 2E ]
.text           axrb2mo2.SYS                                                                                           B935B3CB 9 Bytes  [ 00, 00, 5A, 02, 00, 00, 00, ... ]
.text           ...                                                                                                    
?               C:\WINDOWS\system32\drivers\OAnet.sys                                                                  Accesso negato.
?               C:\WINDOWS\system32\drivers\OAmon.sys                                                                  Accesso negato.
?               C:\WINDOWS\system32\drivers\OADriver.sys                                                               Accesso negato.
?               C:\WINDOWS\TEMP\mc21.tmp                                                                               Impossibile trovare il file specificato. !

---- User code sections - GMER 1.0.14 ----

.text           C:\Programmi\a-squared Free\a2service.exe[1192] kernel32.dll!FreeLibrary + 15                          7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe[1476] kernel32.dll!FreeLibrary + 15                7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\SearchIndexer.exe[1636] kernel32.dll!FreeLibrary + 15                              7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\SearchIndexer.exe[1636] kernel32.dll!WriteFile                                     7C810E17 7 Bytes  JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text           C:\Programmi\Eset\nod32krn.exe[1676] kernel32.dll!FreeLibrary + 15                                     7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\nvsvc32.exe[1756] kernel32.dll!FreeLibrary + 15                                    7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!LoadLibraryExW                                              7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessW                                              7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessA                                              7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\WINDOWS\Explorer.EXE[1780] USER32.dll!ExitWindowsEx                                                 7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\WINDOWS\system32\svchost.exe[1928] kernel32.dll!FreeLibrary + 15                                    7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Online Armor\oaui.exe[2596] kernel32.dll!FreeLibrary + 15                                 7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!LoadLibraryExW                                       7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!CreateProcessW                                       7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!CreateProcessA                                       7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!FreeLibrary + 15                                     7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Eset\nod32kui.exe[2696] USER32.dll!ExitWindowsEx                                          7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!LoadLibraryExW                             7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!CreateProcessW                             7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!CreateProcessA                             7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!FreeLibrary + 15                           7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Mozilla Firefox\firefox.exe[2804] USER32.dll!ExitWindowsEx                                7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!LoadLibraryExW                                     7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!CreateProcessW                                     7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!CreateProcessA                                     7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!FreeLibrary + 15                                   7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\RUNDLL32.EXE[2916] USER32.dll!ExitWindowsEx                                        7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!LoadLibraryExW                  7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!CreateProcessW                  7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!CreateProcessA                  7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!FreeLibrary + 15                7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] USER32.dll!ExitWindowsEx                     7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!LoadLibraryExW                                       7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!CreateProcessW                                       7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!CreateProcessA                                       7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!FreeLibrary + 15                                     7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\ctfmon.exe[3036] USER32.dll!ExitWindowsEx                                          7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!LoadLibraryExW                  7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!CreateProcessW                  7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!CreateProcessA                  7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!FreeLibrary + 15                7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] USER32.dll!ExitWindowsEx                     7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!LoadLibraryExW                  7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!CreateProcessW                  7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!CreateProcessA                  7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!FreeLibrary + 15                7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] USER32.dll!ExitWindowsEx                     7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!LoadLibraryExW                                    7C801AF5 6 Bytes  JMP 5F070F5A 
.text           E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!CreateProcessW                                    7C802336 6 Bytes  JMP 5F0A0F5A 
.text           E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!CreateProcessA                                    7C80236B 6 Bytes  JMP 5F040F5A 
.text           E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!FreeLibrary + 15                                  7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] user32.dll!ExitWindowsEx                                       7E3DA275 6 Bytes  JMP 5F0D0F5A 
.text           C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!LoadLibraryExW                                     7C801AF5 6 Bytes  JMP 5F070F5A 
.text           C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!CreateProcessW                                     7C802336 6 Bytes  JMP 5F0A0F5A 
.text           C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!CreateProcessA                                     7C80236B 6 Bytes  JMP 5F040F5A 
.text           C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!FreeLibrary + 15                                   7C80AC83 4 Bytes  [ B5, 53, 7F, E2 ]
.text           C:\WINDOWS\system32\rundll32.exe[3788] USER32.dll!ExitWindowsEx                                        7E3DA275 6 Bytes  JMP 5F0D0F5A 

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT             atapi.sys[HAL.dll!READ_PORT_UCHAR]                                                                     [BA6A9040] spcu.sys
IAT             atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT]                                                             [BA6A913C] spcu.sys
IAT             atapi.sys[HAL.dll!READ_PORT_USHORT]                                                                    [BA6A90BE] spcu.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT]                                                            [BA6A97FC] spcu.sys
IAT             atapi.sys[HAL.dll!WRITE_PORT_UCHAR]                                                                    [BA6A96D2] spcu.sys
IAT             \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR]                                     [BA6B9048] spcu.sys
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfAcquireSpinLock]                                   C0840CEC
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_UCHAR]                                     053C0D74
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KeGetCurrentIrql]                                    57B80974
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfRaiseIrql]                                         8B000000
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfLowerIrql]                                         56C35DE5
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!HalGetInterruptVector]                               8D08758B
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!HalTranslateBusAddress]                              8D51FC4D
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KeStallExecutionProcessor]                           8D52FD55
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfReleaseSpinLock]                                   8D51FE4D
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_BUFFER_USHORT]                             8D52FF55
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_USHORT]                                    8D51F84D
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT]                            5052F455
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!WRITE_PORT_UCHAR]                                    EACAE856
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[WMILIB.SYS!WmiSystemControl]                                 0FC08520
IAT             \SystemRoot\System32\Drivers\axrb2mo2.SYS[WMILIB.SYS!WmiCompleteRequest]                               0001B185
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter]                                      [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter]                                       [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol]                                  [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol]                               [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol]                                 [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter]                                      [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter]                                     [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter]                                    [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter]                                     [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol]                              [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol]                                [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol]                                [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol]                              [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter]                                    [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT             \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter]                                     [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys

---- Devices - GMER 1.0.14 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                 89B9D1F8

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                 amon.sys (Amon monitor/Eset )

Device          \Driver\Tcpip \Device\Ip                                                                               OAmon.sys
Device          \Driver\usbohci \Device\USBPDO-0                                                                       899E71F8
Device          \Driver\dmio \Device\DmControl\DmIoDaemon                                                              89C101F8
Device          \Driver\dmio \Device\DmControl\DmConfig                                                                89C101F8
Device          \Driver\dmio \Device\DmControl\DmPnP                                                                   89C101F8
Device          \Driver\dmio \Device\DmControl\DmInfo                                                                  89C101F8
Device          \Driver\usbehci \Device\USBPDO-1                                                                       899D31F8
Device          \Driver\usbohci \Device\USBPDO-2                                                                       899E71F8
Device          \Driver\usbehci \Device\USBPDO-3                                                                       899D31F8
Device          \Driver\Tcpip \Device\Tcp                                                                              OAmon.sys
Device          \Driver\Ftdisk \Device\HarddiskVolume1                                                                 89B9F1F8
Device          \Driver\Ftdisk \Device\HarddiskVolume2                                                                 89B9F1F8
Device          \Driver\Cdrom \Device\CdRom0                                                                           899901F8
Device          \Driver\Cdrom \Device\CdRom1                                                                           899901F8
Device          \Driver\NetBT \Device\NetBT_Tcpip_{9A69858B-9555-4863-82DB-C726B1D67EB5}                               89884500
Device          \Driver\NetBT \Device\NetBt_Wins_Export                                                                89884500
Device          \Driver\PCI_PNP5288 \Device\0000004c                                                                   spcu.sys
Device          \Driver\sptd \Device\2297184038                                                                        spcu.sys
Device          \Driver\Tcpip \Device\Udp                                                                              OAmon.sys
Device          \Driver\Tcpip \Device\RawIp                                                                            OAmon.sys
Device          \Driver\usbohci \Device\USBFDO-0                                                                       899E71F8
Device          \Driver\usbehci \Device\USBFDO-1                                                                       899D31F8
Device          \FileSystem\MRxSmb \Device\LanmanDatagramReceiver                                                      8828A1F8
Device          \Driver\Tcpip \Device\IPMULTICAST                                                                      OAmon.sys
Device          \Driver\usbohci \Device\USBFDO-2                                                                       899E71F8
Device          \Driver\NetBT \Device\NetBT_Tcpip_{8BBCD01E-87B9-4F65-9932-7DDAF8D14EF5}                               89884500
Device          \FileSystem\MRxSmb \Device\LanmanRedirector                                                            8828A1F8
Device          \Driver\usbehci \Device\USBFDO-3                                                                       899D31F8
Device          \Driver\Ftdisk \Device\FtControl                                                                       89B9F1F8
Device          \Driver\axrb2mo2 \Device\Scsi\axrb2mo21Port4Path0Target0Lun0                                           898651F8
Device          \Driver\axrb2mo2 \Device\Scsi\axrb2mo21                                                                898651F8
Device          \FileSystem\Cdfs \Cdfs                                                                                 886AE500

---- Registry - GMER 1.0.14 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1                                                     771343423
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2                                                     285507792
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0                                                     1
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                       
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                    C:\Programmi\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                    0
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                 0x52 0x40 0x14 0x4E ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001              
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0           0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh        0x10 0xA4 0xCD 0x94 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40        
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh  0x3A 0x7D 0xEF 0x5B ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                           
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                        C:\Programmi\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                        0
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                     0x52 0x40 0x14 0x4E ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                  
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0               0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh            0x10 0xA4 0xCD 0x94 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40            
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh      0x3A 0x7D 0xEF 0x5B ...

---- EOF - GMER 1.0.14 ----
Taxon è offline   Rispondi citando il messaggio o parte di esso
 Rispondi


DJI Romo, il robot aspirapolvere tutto trasparente DJI Romo, il robot aspirapolvere tutto trasparen...
DJI Osmo Nano: la piccola fotocamera alla prova sul campo DJI Osmo Nano: la piccola fotocamera alla prova ...
FUJIFILM X-T30 III, la nuova mirrorless compatta FUJIFILM X-T30 III, la nuova mirrorless compatta
Oracle AI World 2025: l'IA cambia tutto, a partire dai dati Oracle AI World 2025: l'IA cambia tutto, a parti...
Micron e millisecondi: la piattaforma ServiceNow guida l'infrastruttura IT di Aston Martin F1 Micron e millisecondi: la piattaforma ServiceNow...
Mercato auto europeo in crescita nei pri...
Addio SSD e RAM, benvenuti funghi: dagli...
TCL Q6C: tecnologia e design per un TV c...
Corsair MP700 PRO XT al debutto: un SSD ...
Apple Watch Ultra 2 in titanio con GPS +...
Nuova protezione per Windows 11: scansio...
GoPro LIT HERO a 249€ su Amazon: la nuov...
PayPal integra i pagamenti in ChatGPT: c...
Battlefield REDSEC: al via la Stagione 1...
Dark Power 14 è un alimentatore d...
Ufficiale: Amazon taglia 14.000 posti di...
Firefox verso la trasparenza totale: i n...
Final Fantasy 7 Remake Part 3: arrivano ...
Elon Musk vuole 1.000 miliardi: il consi...
Il pixel più piccolo al mondo: un...
Chromium
GPU-Z
OCCT
LibreOffice Portable
Opera One Portable
Opera One 106
CCleaner Portable
CCleaner Standard
Cpu-Z
Driver NVIDIA GeForce 546.65 WHQL
SmartFTP
Trillian
Google Chrome Portable
Google Chrome 120
VirtualBox
Tutti gli articoli Tutte le news Tutti i download

Strumenti

Regole
Non Puoi aprire nuove discussioni
Non Puoi rispondere ai messaggi
Non Puoi allegare file
Non Puoi modificare i tuoi messaggi

Il codice vB è On
Le Faccine sono On
Il codice [IMG] è On
Il codice HTML è Off
Vai al Forum


Tutti gli orari sono GMT +1. Ora sono le: 15:32.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Served by www3v