|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#141 |
|
Senior Member
Iscritto dal: Mar 2007
Messaggi: 2448
|
ragazzi,una domanda... se non ho nemmeno UNA voce in rosso dopo scansione, non dovrei avere rootkit,vero? insomma,quante probabilita ci sono che un rootkit non lasci neanche una traccia in rosso?
__________________
CASE: Aerocool CS-107 v2 | CPU: AMD Ryzen 7 5700x | MB: ASUS TUF Gaming B550M-Plus | GPU: SAPPHIRE Radeon RX 570 Pulse ITX 4GB | RAM: G.Skill RipjawsV DDR4 3200-C15 16GB | NMVE: Samsung 970 EVO M.2 250GB | SSD1: Crucial MX500 250GB | SSD2: Silicon Power A55 2TB | MAST.: LG GP57EB40 | FANS: 3x Thermalright TL-C12C | ALI: Be Quiet! Pure Power 11 CM500W | AUDIO: Audient iD4 MKII | 2.0 M-Audio BX8 D2 | OS1: EndeavourOS | OS2: Linux Mint 21.3 | OS3: Windows 11 Pro |
|
|
|
|
|
#142 | ||
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Quote:
Quote:
Link utili: http://www.hwupgrade.it/forum/showth...hlight=ROOTKIT http://www.hwupgrade.it/forum/showth...5BNEWS%5D+TEST
__________________
Try again and you will be luckier.
Ultima modifica di Chill-Out : 31-03-2008 alle 19:16. |
||
|
|
|
|
|
#143 |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 2171
|
Ciao, vi posto il mio log, grazie della vostra disponibilita'
Codice:
GMER 1.0.14.14205 - http://www.gmer.net
Rootkit scan 2008-04-06 02:37:35
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwClose [0xF744C028]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreateKey [0xF744BFE0]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwCreatePagingFile [0xF743FB00]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateKey [0xF74405DC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwEnumerateValueKey [0xF744C120]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenFile [0xF743FB40]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwOpenKey [0xF744BFA4]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryKey [0xF74405FC]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwQueryValueKey [0xF744C076]
SSDT a347bus.sys (Plug and Play BIOS Extension/ ) ZwSetSystemPowerState [0xF744B550]
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28DAA 7C9D2175 260 Bytes [ BD, E4, 77, DE, 82, E4, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28EAF 7C9D227A 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE28EB1 7C9D227C 584 Bytes [ 85, F1, D3, 77, 04, 06, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE290FA 7C9D24C5 383 Bytes [ 01, D4, 77, 6E, B4, D1, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + FFE2927A 7C9D2645 168 Bytes [ 85, D3, 77, 9F, 01, D2, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 1C2 7C9F2AC3 274 Bytes [ 53, 48, 46, 69, 6E, 64, 5F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 2D5 7C9F2BD6 118 Bytes [ 53, 48, 47, 65, 74, 46, 69, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 34C 7C9F2C4D 16 Bytes [ 53, 48, 47, 65, 74, 46, 6F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 35D 7C9F2C5E 94 Bytes [ 53, 48, 47, 65, 74, 49, 63, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFree + 3BC 7C9F2CBD 62 Bytes [ 53, 48, 47, 65, 74, 4E, 65, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + C0 7C9F30BD 48 Bytes [ 53, 48, 53, 68, 65, 6C, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + F1 7C9F30EE 117 Bytes [ 53, 48, 53, 74, 61, 72, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadOLE + 167 7C9F3164 217 Bytes [ 53, 48, 56, 61, 6C, 69, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 9 7C9F323E 386 Bytes [ 53, 68, 65, 53, 65, 74, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 18C 7C9F33C1 165 Bytes [ 74, 72, 43, 68, 72, 49, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILClone + 232 7C9F3467 72 Bytes [ 53, 74, 72, 52, 43, 68, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCloneFirst + 12 7C9F34B0 218 Bytes [ 53, 74, 72, 53, 74, 72, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 3C 7C9F358B 68 Bytes [ 68, 49, 73, 52, 65, 6C, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 81 7C9F35D0 56 Bytes [ 55, 8B, EC, FF, 75, 08, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + BD 7C9F360C 67 Bytes [ 8B, FF, 55, 8B, EC, 53, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 101 7C9F3650 21 Bytes [ 00, 00, 8B, F8, 39, 1D, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCombine + 117 7C9F3666 116 Bytes [ 15, 68, 1A, 9D, 7C, 5E, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 64 7C9F3C02 4 Bytes [ 80, 89, 7D, 0C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 69 7C9F3C07 1 Byte [ 15 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 6B 7C9F3C09 18 Bytes [ 1B, 9D, 7C, FF, 75, 10, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + 7E 7C9F3C1C 57 Bytes [ F8, 50, 53, FF, 75, 08, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDesktopFolder + B8 7C9F3C56 29 Bytes [ 8B, C7, 5F, 5E, C9, C2, 0C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 1 7C9F4590 45 Bytes JMP 7097D097
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 31 7C9F45C0 63 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 71 7C9F4600 21 Bytes [ 00, 8B, 45, 0C, C9, C2, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 87 7C9F4616 22 Bytes [ 8B, C1, 8D, 50, 04, C7, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRestricted + 9E 7C9F462D 12 Bytes [ 00, 0F, 85, 90, 8C, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 12 7C9F4EE6 26 Bytes [ 5F, 5E, 8B, C3, 5B, 5D, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 2D 7C9F4F01 10 Bytes [ 00, 73, 00, 65, 00, 44, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 38 7C9F4F0C 45 Bytes [ 6B, 00, 74, 00, 6F, 00, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 66 7C9F4F3A 13 Bytes [ 63, 00, 79, 00, 4C, 00, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILRemoveLastID + 74 7C9F4F48 27 Bytes [ 68, 00, 61, 00, 76, 00, 69, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 19 7C9F50F6 12 Bytes [ 45, 00, 76, 00, 65, 00, 6E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 26 7C9F5103 4 Bytes [ 00, 49, 00, 6E ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 2B 7C9F5108 7 Bytes [ 68, 00, 65, 00, 72, 00, 69 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 33 7C9F5110 47 Bytes [ 74, 00, 43, 00, 6F, 00, 6E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetSettings + 63 7C9F5140 19 Bytes [ 62, 00, 56, 00, 69, 00, 65, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 66 7C9F5546 51 Bytes [ 70, 00, 53, 00, 63, 00, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 9A 7C9F557A 104 Bytes [ 75, 00, 6E, 00, 64, 00, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 104 7C9F55E4 60 Bytes [ 08, 00, 00, 00, 10, 58, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 141 7C9F5621 49 Bytes [ 01, 00, 00, 10, 58, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCLSIDFromString + 173 7C9F5653 24 Bytes [ 00, 10, 58, 9D, 7C, E0, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 2A 7C9F56D5 13 Bytes [ 00, 00, 01, 10, 58, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 38 7C9F56E3 107 Bytes [ 02, 10, 58, 9D, 7C, 38, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + A4 7C9F574F 79 Bytes [ 40, 10, 58, 9D, 7C, 20, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + F5 7C9F57A0 109 Bytes [ 09, 00, 00, 40, 10, 58, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindLastID + 164 7C9F580F 46 Bytes [ 40, 00, 53, 9D, 7C, B0, 51, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 1B 7C9F6872 111 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 8B 7C9F68E2 2 Bytes [ 21, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + 8F 7C9F68E6 19 Bytes [ 3B, C7, 5F, 0F, 85, FD, 24, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + A3 7C9F68FA 63 Bytes [ C0, 75, 03, 8D, 46, 20, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHParseDisplayName + E4 7C9F693B 66 Bytes [ 45, 0C, 5D, C2, 0C, 00, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + 6C 7C9F6E93 31 Bytes [ C5, BC, 7C, 89, 45, FC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + 8C 7C9F6EB3 27 Bytes CALL 7C9F6E58 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + A8 7C9F6ECF 46 Bytes [ 00, 00, 8B, D8, 8B, 4D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + D8 7C9F6EFF 32 Bytes [ 8B, 45, 14, 53, 8B, 5D, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHILCreateFromPath + F9 7C9F6F20 69 Bytes [ 00, 8D, BD, E4, FB, FF, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath 7C9F6FBF 74 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 4B 7C9F700A 87 Bytes [ 45, 0C, 57, 8B, F1, 50, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + A3 7C9F7062 101 Bytes [ 33, C0, 8B, 4D, FC, 5F, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 109 7C9F70C8 49 Bytes [ 50, 56, 89, 85, D8, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPath + 13B 7C9F70FA 25 Bytes CALL 7C9F6FC3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + 12 7C9F78BF 138 Bytes [ 7D, 14, 8B, F0, 89, 7D, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + 9D 7C9F794A 2 Bytes [ 5D, 14 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + A0 7C9F794D 58 Bytes [ 45, E4, 8B, 45, 18, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + DC 7C9F7989 18 Bytes [ FF, 75, D8, 8B, 46, 18, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfoW + EF 7C9F799C 5 Bytes [ 57, 0C, 8B, F8, 85 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 16 7C9F7AA0 12 Bytes [ 75, C0, 50, FF, 51, 0C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 23 7C9F7AAD 54 Bytes [ 75, C4, 8D, 45, D0, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 5A 7C9F7AE4 67 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 9E 7C9F7B28 177 Bytes [ 50, 8D, 45, F4, 50, 53, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFree + 150 7C9F7BDA 12 Bytes [ 75, 20, FF, 75, 08, FF, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 10 7C9F7F1E 89 Bytes [ 64, 00, 69, 00, 6E, 00, 67, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 6A 7C9F7F78 4 Bytes [ 66, C7, 03, 19 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 6F 7C9F7F7D 25 Bytes [ C6, 43, 02, 2F, 75, 14, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + 89 7C9F7F97 31 Bytes [ 33, FF, 8B, 4D, FC, 8B, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderPathW + AB 7C9F7FB9 15 Bytes [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + E 7C9F869C 5 Bytes [ FF, 75, 08, E8, 59 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 14 7C9F86A2 100 Bytes [ 00, 00, 85, C0, 75, 41, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 79 7C9F8707 10 Bytes [ 00, A1, 08, C5, BC, 7C, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 85 7C9F8713 6 Bytes [ 00, 56, 89, 45, FC, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathW + 8C 7C9F871A 23 Bytes [ 08, 57, 50, 8B, F9, E8, 17, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 28 7C9F9829 35 Bytes [ 83, BD, EC, FD, FF, FF, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 4C 7C9F984D 43 Bytes [ 00, 33, DB, 66, 39, 1E, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderLocation + 79 7C9F987A 84 Bytes CALL 7C9F091D C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 4C 7C9F98CF 13 Bytes [ 85, FC, FD, FF, FF, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 5A 7C9F98DD 4 Bytes [ B5, EC, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 5F 7C9F98E2 1 Byte [ 8D ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 61 7C9F98E4 5 Bytes [ FC, FD, FF, FF, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSpecialFolderLocation + 67 7C9F98EA 11 Bytes [ 15, 7C, 20, 9D, 7C, 83, BD, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 11 7C9F9A7D 5 Bytes [ 0C, 8D, 8D, DC, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 17 7C9F9A83 40 Bytes CALL 7C9F9A85 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 40 7C9F9AAC 25 Bytes [ 5F, 5E, 5B, 74, 0C, FF, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 5A 7C9F9AC6 8 Bytes CALL 7C9F0920 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsEqual + 63 7C9F9ACF 4 Bytes [ 90, 90, 90, 90 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 15 7C9F9D91 6 Bytes [ C5, BC, 7C, 89, 45, FC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 1C 7C9F9D98 44 Bytes [ 45, 08, 50, 6A, 07, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 49 7C9F9DC5 44 Bytes [ 85, C0, 0F, 85, 19, B1, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 76 7C9F9DF2 31 Bytes CALL 7C9F9A1E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDListW + 96 7C9F9E12 29 Bytes [ C0, 0F, 84, 7C, 6E, 02, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealDriveType + 1E 7C9F9E9C 23 Bytes [ 34, 50, FF, 76, 14, E8, 63, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType 7C9F9EB6 24 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 19 7C9F9ECF 18 Bytes [ 76, 04, FF, 75, 0C, 53, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 2C 7C9F9EE2 69 Bytes [ 74, 2C, 6A, 00, 8D, 45, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 72 7C9F9F28 10 Bytes [ FF, 55, 8B, EC, 8B, 45, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DriveType + 7D 7C9F9F33 29 Bytes [ 7F, 0F, 87, CF, 5D, 06, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + B 7C9FA04A 151 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + A4 7C9FA0E3 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + A8 7C9FA0E7 122 Bytes [ EC, 51, 83, 65, FC, 00, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + 123 7C9FA162 24 Bytes [ C7, 5F, 5E, C9, C3, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsNetDrive + 13C 7C9FA17B 1 Byte [ 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 3C 7C9FADA4 91 Bytes [ C5, BC, 7C, 56, 8B, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 98 7C9FAE00 16 Bytes [ B5, E0, FD, FF, FF, E8, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + A9 7C9FAE11 55 Bytes [ 85, E0, FD, FF, FF, 8D, 95, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + E1 7C9FAE49 56 Bytes [ 8B, 85, E0, FD, FF, FF, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetClassObject + 11A 7C9FAE82 3 Bytes [ EC, 83, EC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 2 7C9FAFF2 11 Bytes CALL 7C9FB4F4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + F 7C9FAFFF 37 Bytes [ FC, 66, F7, D8, 5F, 5E, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 37 7C9FB027 19 Bytes CALL 7C9F3A80 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 4B 7C9FB03B 5 Bytes [ 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCoCreateInstance + 51 7C9FB041 30 Bytes [ 55, 8B, EC, 81, EC, 14, 02, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetImageLists + 5E 7C9FB158 32 Bytes [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetImageLists + 80 7C9FB17A 49 Bytes [ 00, 53, 8B, 5D, 18, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 27 7C9FB1AC 45 Bytes [ 00, 8D, 85, F4, F5, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 55 7C9FB1DA 107 Bytes [ FF, C9, C2, 18, 00, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + C1 7C9FB246 67 Bytes [ C4, FF, FF, 8D, 85, E4, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 105 7C9FB28A 29 Bytes [ 8B, 55, 10, A1, 08, C5, BC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBindToParent + 123 7C9FB2A8 106 Bytes [ 08, 51, 33, FF, 50, 57, 89, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath 7C9FB4F4 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 4 7C9FB4F8 47 Bytes [ FF, 55, 8B, EC, 56, 8B, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 34 7C9FB528 10 Bytes [ C6, 5E, 5D, C2, 08, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSimpleIDListFromPath + 3F 7C9FB533 62 Bytes [ 8B, FF, 55, 8B, EC, 81, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 25 7C9FB572 29 Bytes [ FF, C9, C2, 08, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 43 7C9FB590 30 Bytes [ 8B, F1, 47, 83, BE, A4, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 62 7C9FB5AF 107 Bytes [ FF, 8D, 85, EC, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + CE 7C9FB61B 170 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowW + 179 7C9FB6C6 20 Bytes [ C7, 06, 80, 7A, 9D, 7C, 74, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILIsParent + A2 7C9FB7B9 116 Bytes [ 4D, 10, 56, 8B, 75, 0C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 57 7C9FB82E 5 Bytes [ C6, 5E, 5D, C2, 0C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 5D 7C9FB834 8 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 66 7C9FB83D 10 Bytes [ EC, 56, 57, 68, 98, 04, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 71 7C9FB848 12 Bytes [ FF, FF, 85, C0, 59, 74, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILFindChild + 7E 7C9FB855 7 Bytes [ 75, 0C, FF, 75, 08, E8, 8F ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 13 7C9FE90C 38 Bytes [ 83, 7B, 34, 00, 74, 0C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 3A 7C9FE933 54 Bytes [ 80, 74, 17, 5F, 5E, 5B, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 71 7C9FE96A 13 Bytes [ 07, 33, C0, 5E, 5D, C2, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + 7F 7C9FE978 83 Bytes CALL 7C9F4659 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyRegister + D3 7C9FE9CC 42 Bytes [ 4B, FF, FF, 85, C0, 59, 74, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 4 7C9FF77B 5 Bytes [ 75, 08, 83, 7E, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + A 7C9FF781 49 Bytes [ 74, 1B, 8D, 45, 14, 50, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 3C 7C9FF7B3 1 Byte [ F4 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 40 7C9FF7B7 1 Byte [ 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_MergeMenus + 42 7C9FF7B9 2 Bytes [ 76, BD ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 11 7CA0067F 37 Bytes CALL 7C9FCD0D C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 37 7CA006A5 302 Bytes [ A8, 20, 0F, 85, 84, 53, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 167 7CA007D5 41 Bytes [ B8, 05, 40, 00, 80, 74, 30, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 191 7CA007FF 5 Bytes [ 75, 10, FF, 75, 0C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderView + 198 7CA00806 54 Bytes [ 08, 50, FF, 51, 1C, 5B, 5E, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 23 7CA06AFA 24 Bytes [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 3C 7CA06B13 31 Bytes [ 06, 8B, D9, 57, 8D, 7B, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + 5C 7CA06B33 130 Bytes [ 55, 8B, EC, 81, EC, 28, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + DF 7CA06BB6 1 Byte [ 61 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_GetCachedImageIndex + E1 7CA06BB8 1 Byte [ 6E ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + B1 7CA07377 18 Bytes [ 55, 8B, EC, 8B, 45, 08, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + C6 7CA0738C 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + CC 7CA07392 49 Bytes [ 45, 08, 56, 57, 8B, 7D, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + FE 7CA073C4 41 Bytes CALL 7C9F6B73 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapIDListToImageListIndexAsync + 128 7CA073EE 61 Bytes [ C8, 23, 4D, 0C, 3B, C8, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + B 7CA07E84 3 Bytes [ C2, 5F, 05 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + F 7CA07E88 1 Byte [ 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 11 7CA07E8A 77 Bytes CALL 061D3B9E
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + 5F 7CA07ED8 65 Bytes [ 0F, 84, 9A, 45, 05, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMapPIDLToSystemImageListIndex + A1 7CA07F1A 48 Bytes [ FF, 55, 8B, EC, 8D, 81, 64, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 2 7CA0997A 29 Bytes JMP 7CA098F4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 20 7CA09998 25 Bytes [ 55, 8B, EC, 83, EC, 40, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 3A 7CA099B2 30 Bytes [ 84, AE, 1B, 00, 00, 56, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconW + 59 7CA099D1 108 Bytes [ 1E, 05, 00, 8D, 45, 0C, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 15 7CA09A3E 10 Bytes [ FF, 43, 83, C7, 1C, 3B, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 20 7CA09A49 23 Bytes [ 76, 38, 68, 02, 00, 00, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 39 7CA09A62 4 Bytes CALL 7CA09838 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 3E 7CA09A67 53 Bytes [ FF, 83, 7E, 3C, 00, 5B, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHExtractIconsW + 75 7CA09A9E 3 Bytes [ 90, 90, 90 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 6 7CA0A619 56 Bytes [ 08, 50, FF, 51, 08, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 3F 7CA0A652 66 Bytes CALL 7C9F5F71 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 82 7CA0A695 19 Bytes [ 07, 80, EB, E0, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + 96 7CA0A6A9 30 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllGetVersion + B5 7CA0A6C8 45 Bytes [ FF, 15, 0C, 13, 9D, 7C, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 24 7CA0A752 23 Bytes [ 8B, 75, 10, F7, C6, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 3C 7CA0A76A 90 Bytes [ 15, 56, 53, FF, B5, EC, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + 97 7CA0A7C5 33 Bytes [ FF, 89, 85, E4, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + BA 7CA0A7E8 2 Bytes [ 85, C0 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Unlock + BD 7CA0A7EB 3 Bytes [ 85, D3, 4A ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 1B 7CA0AC42 64 Bytes [ 90, 90, 90, 90, 90, 90, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 5D 7CA0AC84 41 Bytes [ D0, 9C, A0, 7C, B4, 9C, A0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 87 7CA0ACAE 4 Bytes [ 31, 00, 33, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + 8C 7CA0ACB3 34 Bytes [ 00, 66, 00, 70, 00, 69, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotify + AF 7CA0ACD6 7 Bytes [ 69, 00, 63, 00, 6F, 00, 6E ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 9D 7CA0C403 57 Bytes [ 46, 54, 50, FF, D7, 8B, 8E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + D7 7CA0C43D 111 Bytes [ F1, 6A, 00, FF, 36, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 147 7CA0C4AD 42 Bytes [ 46, 08, 85, C0, 74, 0B, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 172 7CA0C4D8 42 Bytes [ 15, A0, 1C, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILSaveToStream + 19D 7CA0C503 15 Bytes [ FF, 90, 90, 90, 90, 90, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 2C 7CA0D669 19 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 40 7CA0D67D 16 Bytes [ 00, FF, 75, 08, 8B, F1, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 51 7CA0D68E 28 Bytes [ 42, 83, 7E, 54, 00, 75, 0A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 6E 7CA0D6AB 38 Bytes [ 51, 18, 8B, F8, 85, FF, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCloneSpecialIDList + 95 7CA0D6D2 75 Bytes [ C7, 5F, 5E, C9, C2, 04, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 23 7CA0DB6B 18 Bytes [ 85, B0, FB, FF, FF, 83, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 36 7CA0DB7E 14 Bytes [ FF, 85, C0, 0F, 85, 46, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 45 7CA0DB8D 19 Bytes CALL 7CA0DBA4 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + 5C 7CA0DBA4 115 Bytes [ 90, 8B, FF, 55, 8B, EC, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsExe + D0 7CA0DC18 17 Bytes [ 59, 9D, 7C, FF, B5, B4, FB, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 23 7CA0DE8C 9 Bytes [ 85, C0, 74, 1E, 8B, 45, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 2E 7CA0DE97 3 Bytes [ AA, F1, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 32 7CA0DE9B 96 Bytes [ 8D, 48, 04, 6A, 01, E8, F1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + 93 7CA0DEFC 48 Bytes [ 15, 68, 13, 9D, 7C, E9, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDrive + C4 7CA0DF2D 45 Bytes JMP 7CA053AA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 4B 7CA0E774 5 Bytes [ FF, 8B, CE, E8, 0A ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 52 7CA0E77B 5 Bytes [ 00, E9, 52, F6, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 58 7CA0E781 117 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + CE 7CA0E7F7 129 Bytes [ 75, 10, FF, 75, FC, E8, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddToRecentDocs + 150 7CA0E879 95 Bytes [ 59, 33, C0, EB, F1, 8B, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile 7CA0EE68 115 Bytes [ 90, 8B, FF, 55, 8B, EC, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + 74 7CA0EEDC 22 Bytes [ 4D, FC, 5F, 5E, 5B, E8, 3A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + 8B 7CA0EEF3 83 Bytes [ EC, 56, 57, 6A, 01, 33, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + E0 7CA0EF48 23 Bytes [ 00, 8B, F8, F7, C7, 00, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Win32DeleteFile + F8 7CA0EF60 43 Bytes [ 90, E4, 00, 00, 00, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + 2 7CA0F22E 152 Bytes [ 7C, 65, 53, FF, 15, 8C, 1A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + 9B 7CA0F2C7 10 Bytes [ 15, A0, 1A, 9D, 7C, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + A7 7CA0F2D3 76 Bytes [ 33, C0, EB, F8, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + F6 7CA0F322 2 Bytes [ 5F, 5E ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathYetAnotherMakeUniqueName + FA 7CA0F326 1 Byte [ 15 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathCleanupSpec + 79 7CA0F488 11 Bytes [ FF, 15, 00, 13, 9D, 7C, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathCleanupSpec + 85 7CA0F494 66 Bytes CALL 7CA0F679 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 2A 7CA0F4D7 11 Bytes [ B5, DC, FD, FF, FF, 8B, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 36 7CA0F4E3 4 Bytes [ 89, 85, E0, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 3C 7CA0F4E9 1 Byte [ 8D ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 3E 7CA0F4EB 2 Bytes [ F0, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfoW + 42 7CA0F4EF 75 Bytes [ 50, FF, B5, EC, FD, FF, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + D 7CA0FB18 181 Bytes [ 75, 08, FF, 15, A0, 1A, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + C3 7CA0FBCE 25 Bytes [ 53, 8D, 45, FC, 50, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + DD 7CA0FBE8 3 Bytes [ 46, 1C, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + E1 7CA0FBEC 26 Bytes [ 53, FF, 75, FC, FF, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrIW + FC 7CA0FC07 50 Bytes CALL 7CA0FC3C C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + 16 7CA0FCD5 7 Bytes [ B5, D8, F7, FF, FF, 53, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + 1E 7CA0FCDD 159 Bytes [ 18, 85, C0, 0F, 8D, D8, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + BE 7CA0FD7D 4 Bytes [ 85, C0, 7C, 2B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + C3 7CA0FD82 7 Bytes [ 55, 10, 8B, 45, FC, 8B, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifyDeregister + CB 7CA0FD8A 37 Bytes [ E2, 01, F6, DA, 1B, D2, 81, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + 76 7CA1162F 31 Bytes [ 00, 83, 4D, F8, FF, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + 97 7CA11650 30 Bytes [ 00, 89, 7D, F4, 89, 7D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + B6 7CA1166F 14 Bytes [ 01, 6A, 01, FF, 50, 14, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + C5 7CA1167E 46 Bytes [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllCanUnloadNow + F4 7CA116AD 31 Bytes [ 5B, C9, C3, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 2 7CA11FE6 92 Bytes [ 50, 10, 85, C0, 0F, 8C, 31, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 5F 7CA12043 51 Bytes JMP 7CA11C85 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 94 7CA12078 5 Bytes [ 9D, 7C, 2B, F9, C1 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + 9A 7CA1207E 27 Bytes [ 02, 03, F1, 8B, 16, 03, D9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetMalloc + B6 7CA1209A 49 Bytes [ 9D, 7C, 85, D2, 89, 45, FC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + B 7CA136EF 1 Byte [ 8D ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + D 7CA136F1 31 Bytes [ F8, 50, FF, 75, F8, 53, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 2D 7CA13711 56 Bytes [ 15, 8C, 1A, 9D, 7C, 8D, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 66 7CA1374A 32 Bytes [ 15, E4, 20, 9D, 7C, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFileInfo + 87 7CA1376B 6 Bytes [ 15, 28, 19, 9D, 7C, 8B ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 3E 7CA13AB7 35 Bytes CALL 7C9F3A80 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 62 7CA13ADB 318 Bytes [ FD, FF, FF, 50, FF, 15, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 1A1 7CA13C1A 48 Bytes [ 88, 98, 02, 00, 00, 89, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 1D2 7CA13C4B 62 Bytes [ 00, 3B, CA, 0F, 85, 54, FA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetImageList + 211 7CA13C8A 8 Bytes [ C9, C2, 08, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 2 7CA18B23 24 Bytes [ 15, F0, 18, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 1B 7CA18B3C 44 Bytes [ EC, FD, FF, FF, 0F, 8C, 7F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 48 7CA18B69 54 Bytes [ 57, 68, 7D, 00, 00, 40, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + 7F 7CA18BA0 39 Bytes [ F6, 87, 59, 06, 00, 00, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotification_Lock + A7 7CA18BC8 116 Bytes [ F0, 3B, F3, 0F, 8C, 8D, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 1F 7CA19F90 103 Bytes CALL 7CA0068E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 87 7CA19FF8 9 Bytes [ 0F, 84, 28, BC, 03, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 91 7CA1A002 52 Bytes CALL 7C9FFFB8 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + C6 7CA1A037 75 Bytes [ 00, 8B, 4E, 14, 6A, 02, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILLoadFromStream + 112 7CA1A083 23 Bytes [ 80, 8E, 11, 02, 00, 00, 04, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 25 7CA1A324 42 Bytes CALL 7C9F968E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 50 7CA1A34F 59 Bytes [ 85, F4, FD, FF, FF, 50, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + 8D 7CA1A38C 27 Bytes [ 01, E4, FD, FF, 50, 68, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + A9 7CA1A3A8 25 Bytes [ FF, FF, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListW + C3 7CA1A3C2 8 Bytes [ 18, 83, 7D, 0C, 00, 8D, 04, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 96 7CA1B0BB 37 Bytes [ 00, 89, 85, F0, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + BC 7CA1B0E1 43 Bytes [ 56, 8B, 75, 14, 83, 26, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + E8 7CA1B10D 40 Bytes [ 75, 10, 8D, 55, 08, 52, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 111 7CA1B136 11 Bytes JMP 7CA0C4E5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetRealIDL + 11D 7CA1B142 23 Bytes [ 55, 8B, EC, 51, 53, 8B, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 59 7CA1C1C4 10 Bytes [ CE, FF, 50, 14, 8B, C7, 5F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 64 7CA1C1CF 9 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 6E 7CA1C1D9 8 Bytes [ EC, 56, 8B, F1, E8, 19, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 77 7CA1C1E2 19 Bytes [ F6, 45, 08, 01, 74, 07, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CommandLineToArgvW + 8B 7CA1C1F6 34 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 5D 7CA1D37A 9 Bytes [ FF, 15, 1C, 18, 9D, 7C, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 67 7CA1D384 6 Bytes [ D8, 0F, 84, 29, 01, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathResolve + 6E 7CA1D38B 277 Bytes [ 8B, 08, 8D, 55, EC, 52, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 2 7CA1D4A1 37 Bytes [ 75, 0C, 68, B4, E0, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 28 7CA1D4C7 62 Bytes [ 75, 0C, 8B, 45, 08, 83, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 67 7CA1D506 6 Bytes [ 68, 20, E1, 9D, 7C, 57 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + 6E 7CA1D50D 62 Bytes CALL 7C9FBE95 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExecutableW + AD 7CA1D54C 71 Bytes [ 6A, 20, 8D, 45, DC, 50, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSettings + 32 7CA1D5F0 12 Bytes [ D0, 8B, 08, 50, FF, 51, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW 7CA1D5FE 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 4 7CA1D602 109 Bytes [ FF, 55, 8B, EC, 56, 57, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 72 7CA1D670 39 Bytes [ 48, 0C, 8B, D1, 57, C1, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 9B 7CA1D699 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteExW + 9F 7CA1D69D 37 Bytes [ FF, 55, 8B, EC, 56, 68, 48, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + F 7CA1FB2B 48 Bytes [ 55, 8B, EC, 81, EC, 90, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 40 7CA1FB5C 4 Bytes [ FF, FF, 51, 8D ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 45 7CA1FB61 2 Bytes [ 7C, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 49 7CA1FB65 19 Bytes [ 51, 6A, 04, 50, 6A, 01, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteEx + 5D 7CA1FB79 79 Bytes [ FF, FF, 74, 11, 6A, 01, 57, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 94 7CA1FED8 56 Bytes [ 53, 00, 68, 00, 65, 00, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + D1 7CA1FF15 405 Bytes [ 8B, FF, 55, 8B, EC, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 267 7CA200AB 246 Bytes [ 00, 56, FF, 75, 0C, E8, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 35E 7CA201A2 68 Bytes [ A1, 08, C5, BC, 7C, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteA + 3A3 7CA201E7 24 Bytes [ 15, 40, 1D, 9D, 7C, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 3A 7CA21BB7 42 Bytes [ 68, 41, 01, 00, 00, 68, AC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 65 7CA21BE2 56 Bytes [ 66, 3B, C3, 66, A3, 48, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + 9E 7CA21C1B 35 Bytes [ FF, 15, 1C, 18, 9D, 7C, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + C2 7CA21C3F 4 Bytes [ 15, 10, 17, 9D ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHTestTokenMembership + C7 7CA21C44 15 Bytes [ 3B, C6, 74, 11, 68, 48, 7F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 14 7CA220E2 31 Bytes [ 50, 68, 28, 11, A2, 7C, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 34 7CA22102 14 Bytes [ 53, 50, 68, 00, 00, 00, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 43 7CA22111 4 Bytes [ 85, 14, 08, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 48 7CA22116 27 Bytes [ 66, 89, 1E, 8B, 4D, FC, 5F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenRegStream + 64 7CA22132 97 Bytes [ 63, 00, 61, 00, 74, 00, 69, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + 10 7CA222D8 81 Bytes [ 00, 83, 7D, 10, 00, A1, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + 62 7CA2232A 68 Bytes [ BF, 10, 43, 9D, 7C, 33, D2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + A7 7CA2236F 14 Bytes [ FF, B5, F0, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + B6 7CA2237E 20 Bytes [ C6, 5F, 8B, 4D, FC, 5E, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconW + CD 7CA22395 41 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 5 7CA23AB6 57 Bytes [ 56, 57, 6A, 01, 6A, 01, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 3F 7CA23AF0 35 Bytes CALL 7C9F38FF C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 63 7CA23B14 29 Bytes JMP 7CA09B63 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + 81 7CA23B32 59 Bytes CALL 7C9F8B87 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetPathFromIDList + BD 7CA23B6E 111 Bytes [ 15, 70, FC, 9E, 7C, 50, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 6A 7CA2461B 8 Bytes [ EC, 10, 53, 56, C7, 45, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 73 7CA24624 5 Bytes [ 00, 00, C6, 45, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 79 7CA2462A 14 Bytes CALL 7CA243CF C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + 88 7CA24639 52 Bytes [ 8B, 75, 08, 6A, 00, 6A, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILGetNext + BD 7CA2466E 10 Bytes [ 68, F8, B0, 9D, 7C, E8, 4B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 55 7CA2496B 6 Bytes [ 04, 59, 33, C0, F3, A7 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 5C 7CA24972 58 Bytes [ E4, 8B, 45, FC, 5F, 5E, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + 97 7CA249AD 65 Bytes [ F8, 3B, FE, 0F, 8C, 2F, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + D9 7CA249EF 2 Bytes [ 0F, 94 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ReadCabinetState + DC 7CA249F2 70 Bytes [ C1, E0, 09, 33, 06, 25, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 25 7CA2A12B 68 Bytes [ 15, 68, AF, 9F, 7C, 83, A0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 6A 7CA2A170 5 Bytes [ 72, EA, FF, 75, FC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + 70 7CA2A176 96 Bytes [ 45, 08, 57, 68, 3A, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + D1 7CA2A1D7 1 Byte [ F0 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgReadMultiple + D3 7CA2A1D9 30 Bytes [ 02, C1, E0, 02, 50, 51, 52, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 31 7CA2B7F5 14 Bytes [ 90, 90, 90, 8B, FF, 53, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 40 7CA2B804 145 Bytes [ 6C, 9D, 7C, C7, 46, 04, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + D2 7CA2B896 49 Bytes [ 00, 8D, 0C, 40, 8D, BC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 104 7CA2B8C8 98 Bytes [ 08, 85, C0, 56, 8B, F1, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_ShowDragImage + 167 7CA2B92B 3 Bytes [ 45, FC, 39 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 23 7CA2BFC9 44 Bytes [ 10, 8B, F8, 8B, 06, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 50 7CA2BFF6 40 Bytes [ C0, 0F, 84, 21, 3B, 03, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + 79 7CA2C01F 43 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + A5 7CA2C04B 14 Bytes [ 56, FF, 35, 64, C5, BC, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsUserAnAdmin + B4 7CA2C05A 49 Bytes [ 15, 1C, 16, 9D, 7C, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 19 7CA2C890 17 Bytes CALL 7CA2C89F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 2B 7CA2C8A2 79 Bytes [ 55, 8B, EC, 83, EC, 7C, A1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + 7B 7CA2C8F2 57 Bytes [ D7, 85, C0, 75, 5E, FF, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + B5 7CA2C92C 9 Bytes CALL 7CA0F6D7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathProcessCommand + BF 7CA2C936 145 Bytes [ 45, 8C, 8B, 08, 50, FF, 51, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 3D 7CA2FD4E 48 Bytes [ C1, FD, FF, FF, 08, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 6E 7CA2FD7F 27 Bytes [ 76, 28, 33, DB, 8D, 85, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 8A 7CA2FD9B 13 Bytes [ F1, FF, FF, 8B, 85, F4, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + 98 7CA2FDA9 30 Bytes [ 40, 89, 85, F8, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFileAorW + B7 7CA2FDC8 103 Bytes [ FF, FF, 8D, 4E, FC, E8, 46, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 2F 7CA39578 75 Bytes JMP 7CA399C9 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 7C 7CA395C5 4 Bytes [ 8B, 4B, 64, 6A ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 81 7CA395CA 9 Bytes [ 6A, FF, 56, 6A, 01, E8, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 8B 7CA395D4 3 Bytes [ 83, 7B, 64 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListA + 8F 7CA395D8 5 Bytes [ 0F, 84, EB, 03, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 37 7CA3BB45 7 Bytes [ 00, 33, C9, E9, 14, FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 3F 7CA3BB4D 25 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 5A 7CA3BB68 56 Bytes [ FF, 86, 0C, 01, 00, 00, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 93 7CA3BBA1 155 Bytes [ E2, FF, FF, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetSetFolderCustomSettingsW + 130 7CA3BC3E 66 Bytes [ 90, 90, 90, 90, 90, 6A, 20, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 32 7CA40E0E 2 Bytes [ A0, 1A ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 36 7CA40E12 26 Bytes [ F6, 86, 12, 02, 00, 00, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirW + 51 7CA40E2D 91 Bytes [ FC, FF, 6A, 16, FF, 15, C8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 2C 7CA40E89 85 Bytes [ 15, 68, 1A, 9D, 7C, 5F, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 82 7CA40EDF 10 Bytes [ 15, 28, C3, BC, 7C, 8D, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 8D 7CA40EEA 15 Bytes CALL 7CA40F2E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + 9D 7CA40EFA 5 Bytes [ 08, 50, FF, 91, 94 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExW + A3 7CA40F00 90 Bytes [ 00, 00, 57, 57, 8B, D8, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 5 7CA418F4 190 Bytes [ 00, 85, C0, 0F, 84, A2, F9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + C4 7CA419B3 21 Bytes JMP 7CA215AD C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + DA 7CA419C9 71 Bytes JMP 7C9FDF59 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 122 7CA41A11 28 Bytes [ 45, F8, 50, 68, A0, 98, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateRecycleBinIcon + 140 7CA41A2F 18 Bytes CALL 7CA41A4F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + 17 7CA4352D 2 Bytes [ 88, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + 1B 7CA43531 133 Bytes [ 6A, 07, 59, 33, F6, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + A3 7CA435B9 28 Bytes [ 8B, 85, 8C, FD, FF, FF, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + C0 7CA435D6 40 Bytes [ C9, C2, 10, 00, FF, 76, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetLocalizedName + E9 7CA435FF 28 Bytes [ 50, 68, 8C, 59, 9D, 7C, 68, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 2B 7CA43673 66 Bytes CALL 7CA4367A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 6E 7CA436B6 53 Bytes [ 55, 8B, EC, FF, 75, 10, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + A4 7CA436EC 25 Bytes [ E0, 8D, 45, 08, 50, 8B, CB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + BE 7CA43706 185 Bytes [ EC, 83, EC, 2C, A1, 08, C5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushSFCache + 178 7CA437C0 39 Bytes [ 55, 8B, EC, 83, 7D, 0C, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + B 7CA45FE3 103 Bytes [ D8, 8B, C7, 69, C0, E8, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 73 7CA4604B 24 Bytes [ 15, 3C, 12, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 8C 7CA46064 140 Bytes [ 74, 30, FF, 75, 30, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 119 7CA460F1 44 Bytes [ 35, 64, C5, BC, 7C, C7, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractVersionResource16W + 146 7CA4611E 11 Bytes [ 8D, 46, 01, 6A, 05, 89, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 83 7CA478DD 19 Bytes [ BC, 98, D4, 02, 00, 00, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 97 7CA478F1 138 Bytes [ 15, 84, 1A, 9D, 7C, 8B, F0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 123 7CA4797D 25 Bytes [ FF, 75, 18, 8B, 4D, 08, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 13D 7CA47997 42 Bytes [ D2, 8B, 4D, 08, 75, 13, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteW + 168 7CA479C2 36 Bytes [ 75, 0C, FF, 15, C8, 13, 9D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + A 7CA47C25 82 Bytes [ 00, 00, 83, F8, F9, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + 5D 7CA47C78 70 Bytes CALL 7CA07EE7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + A5 7CA47CC0 10 Bytes [ 57, FF, 15, 2C, 13, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + B0 7CA47CCB 9 Bytes [ FF, 6A, 01, 8B, CE, E8, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstW + BB 7CA47CD6 84 Bytes [ 15, 0C, 14, 9D, 7C, 3B, 86, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 4A 7CA47D2B 83 Bytes [ 80, 5D, C2, 10, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 9E 7CA47D7F 5 Bytes [ 75, 0C, 8B, 08, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + A4 7CA47D85 25 Bytes [ 51, 40, 5D, C2, 08, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + BE 7CA47D9F 65 Bytes [ 91, A4, 00, 00, 00, 5D, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIconW + 100 7CA47DE1 18 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 1E 7CA483CE 11 Bytes [ B5, E4, FD, FF, FF, FF, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 2A 7CA483DA 44 Bytes [ 15, B0, 98, A4, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 57 7CA48407 25 Bytes [ FF, B5, E0, FD, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + 71 7CA48421 14 Bytes [ 7C, 9E, FF, B5, D8, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathA + BC 7CA4846C 141 Bytes CALL 7CA47FCC C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 61 7CA484FA 26 Bytes [ 57, FF, 15, D4, 12, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 7D 7CA48516 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + 81 7CA4851A 66 Bytes [ FF, 55, 8B, EC, 56, 6A, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + C4 7CA4855D 11 Bytes JMP 7CA47FB7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateQueryCancelAutoPlayMoniker + D0 7CA48569 14 Bytes [ FF, 55, 8B, EC, 81, EC, 0C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 24 7CA48A0B 47 Bytes [ C7, 85, AC, FB, FF, FF, 3C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 54 7CA48A3B 58 Bytes [ FF, 04, 8D, 85, AC, FB, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 8F 7CA48A76 84 Bytes [ FF, 55, 8B, EC, 83, 3D, 3C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + E5 7CA48ACC 37 Bytes [ FF, 75, 08, FF, 76, 08, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Shell_NotifyIcon + 10B 7CA48AF2 17 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 3C 7CA492A5 73 Bytes [ 00, 00, 5F, 5E, 8B, C3, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 86 7CA492EF 41 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + B1 7CA4931A 36 Bytes [ FF, 77, 10, FF, 15, 8C, 13, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + D6 7CA4933F 59 Bytes [ 47, 08, 83, 38, 01, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceExW + 112 7CA4937B 124 Bytes [ 55, 8B, EC, 56, FF, 75, 14, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 1C 7CA49A73 57 Bytes [ FF, 04, 8B, 3D, F0, 20, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 56 7CA49AAD 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 58 7CA49AAF 27 Bytes CALL 7CA48CDD C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 74 7CA49ACB 31 Bytes [ 00, 0F, 84, 69, 08, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconExW + 94 7CA49AEB 36 Bytes [ 00, 0F, 84, A7, F2, FF, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 39 7CA4A270 93 Bytes [ 25, AC, 19, 9D, 7C, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 97 7CA4A2CE 35 Bytes [ FF, 33, C0, 66, 3B, 0F, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + BB 7CA4A2F2 18 Bytes [ A0, C0, 00, 00, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + D1 7CA4A308 85 Bytes CALL 7C9F3779 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragAcceptFiles + 127 7CA4A35E 3 Bytes [ AA, 92, FA ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutW + 40 7CA6F92B 67 Bytes [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 35 7CA6F96F 19 Bytes [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 49 7CA6F983 47 Bytes [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 79 7CA6F9B3 35 Bytes [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + 9D 7CA6F9D7 16 Bytes [ 00, 01, 00, 00, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellAboutA + AE 7CA6F9E8 46 Bytes [ 01, 00, 00, 00, 01, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinW + 55 7CA732CE 62 Bytes [ FF, FF, 15, F8, 20, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 2 7CA7330D 33 Bytes [ 15, 0C, 1A, 9D, 7C, 8D, 86, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 24 7CA7332F 21 Bytes [ 15, F4, B9, 9F, 7C, 83, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 3A 7CA73345 19 Bytes [ FF, 50, FF, 75, 14, E8, E1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 4E 7CA73359 2 Bytes [ 8D, 85 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHQueryRecycleBinA + 51 7CA7335C 66 Bytes [ FB, FF, FF, FF, 75, 10, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 2 7CA7360C 6 Bytes [ FF, 53, E8, 3B, EE, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 9 7CA73613 30 Bytes [ 39, B5, DC, F9, FF, FF, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 29 7CA73633 31 Bytes [ 18, 01, 00, 00, 74, 08, 39, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 4A 7CA73654 14 Bytes CALL 7CA70A88 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinW + 59 7CA73663 62 Bytes [ 8D, 1C, 9D, D8, 18, BD, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 2E 7CA736A2 89 Bytes [ 35, 64, C5, BC, 7C, E8, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 88 7CA736FC 110 Bytes [ 56, 0F, 94, C1, 56, 56, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + F7 7CA7376B 65 Bytes [ FF, 0F, 94, C0, 89, 41, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 139 7CA737AD 5 Bytes [ FF, 8D, 85, DC, F7 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEmptyRecycleBinA + 140 7CA737B4 54 Bytes CALL 7CA71F64 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 18 7CA737EB 112 Bytes [ 85, C0, 0F, 84, 4A, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 89 7CA7385C 183 Bytes [ 8D, 85, DC, F7, FF, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 141 7CA73914 24 Bytes [ D8, BE, 04, 01, 00, 00, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 15A 7CA7392D 13 Bytes [ 08, FE, FF, FF, 50, 57, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateStdEnumFmtEtc + 168 7CA7393B 63 Bytes [ 32, 68, AC, DE, 9D, 7C, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 7E 7CA73B36 54 Bytes [ 15, CC, 20, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + B5 7CA73B6D 15 Bytes [ FF, 00, EB, 0C, FF, 15, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + C5 7CA73B7D 135 Bytes [ 83, BD, BC, F7, FF, FF, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 14D 7CA73C05 7 Bytes [ 15, A4, 20, 9D, 7C, 57, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WriteCabinetState + 155 7CA73C0D 39 Bytes [ B5, D8, F7, FF, FF, 89, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 2E 7CA75A9F 59 Bytes [ FF, 89, 9E, 18, 02, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 6A 7CA75ADB 22 Bytes [ 07, 3B, C3, 74, 09, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 81 7CA75AF2 19 Bytes [ 15, 54, 1A, 9D, 7C, 89, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + 95 7CA75B06 19 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFreeNameMappings + A9 7CA75B1A 20 Bytes [ 76, 04, 33, DB, 89, 5D, FC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectory + 7 7CA7727C 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectory + 9 7CA7727E 18 Bytes [ 41, 56, 8B, 75, 08, 57, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 1 7CA77291 15 Bytes CALL 7CA7712F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 11 7CA772A1 23 Bytes [ FF, 15, DC, 12, 9D, 7C, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 29 7CA772B9 1 Byte [ 15 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 2B 7CA772BB 48 Bytes [ 13, 9D, 7C, 5F, 5E, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateDirectoryExA + 5D 7CA772ED 22 Bytes [ 00, 8B, 51, 34, 85, D2, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 24 7CA7D1DD 27 Bytes [ 00, 8B, 86, A4, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 41 7CA7D1FA 225 Bytes [ 00, C7, 46, 3C, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 123 7CA7D2DC 11 Bytes [ A1, 08, C5, BC, 7C, 53, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 12F 7CA7D2E8 8 Bytes [ FC, 8B, 45, 0C, 57, 8B, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperationW + 138 7CA7D2F1 56 Bytes [ 40, 85, C0, BF, 00, 01, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 4B 7CA7D4EC 41 Bytes [ FF, 8D, 85, F4, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 75 7CA7D516 67 Bytes [ 85, F4, FD, FF, FF, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + B9 7CA7D55A 56 Bytes [ FF, EB, 2B, 8B, 3D, F4, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + F2 7CA7D593 16 Bytes [ FF, 8B, 46, 40, 85, C0, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFileOperation + 103 7CA7D5A4 36 Bytes [ FF, 00, 01, 00, 00, 75, 19, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + 59 7CA7E03E 88 Bytes [ 00, 50, 8D, 86, F4, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + B2 7CA7E097 5 Bytes [ 50, 8D, 86, F4, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLL + B9 7CA7E09E 91 Bytes CALL 7CA783B7 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 20 7CA7E0FA 38 Bytes [ B5, 04, F9, FF, FF, E8, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 47 7CA7E121 29 Bytes [ 83, F8, FF, 74, 11, 8D, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 65 7CA7E13F 11 Bytes [ FF, 68, 04, 01, 00, 00, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 71 7CA7E14B 7 Bytes [ 8D, 85, B4, FD, FF, FF, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_FillCache_RunDLLW + 79 7CA7E153 108 Bytes [ 15, F4, 20, 9D, 7C, 56, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRunControlPanel + E 7CA7ECAF 2 Bytes [ 8B, FE ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHRunControlPanel + 14 7CA7ECB5 1 Byte [ 1C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 5 7CA7ECC1 13 Bytes [ FF, 75, 20, FF, 75, 1C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 13 7CA7ECCF 6 Bytes [ 10, FF, 75, 0C, FF, 75 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 1A 7CA7ECD6 13 Bytes [ 68, 90, 77, 9E, 7C, 68, 58, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLL + 29 7CA7ECE5 87 Bytes [ 5D, C2, 1C, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLW + 28 7CA7ED3D 137 Bytes [ D6, 66, 85, C0, 74, 3C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 59 7CA7EDC7 36 Bytes [ D6, 68, 68, 12, 9E, 7C, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 7F 7CA7EDED 3 Bytes [ EB, 38, 66 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 83 7CA7EDF1 14 Bytes [ 65, BC, 00, 85, DB, 74, 0D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + 92 7CA7EE00 15 Bytes [ 15, 94, 13, 9D, 7C, 83, 65, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Control_RunDLLAsUserW + A2 7CA7EE10 124 Bytes [ 45, B8, 89, 45, B0, 8D, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DuplicateIcon + 33 7CA7F406 47 Bytes [ 83, 20, 00, EB, 4D, 8B, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DuplicateIcon + 63 7CA7F436 136 Bytes [ 9D, 7C, 8B, 85, E4, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FreeIconList + 36 7CA7F4BF 14 Bytes [ 15, CC, 1F, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FreeIconList + 45 7CA7F4CE 55 Bytes [ 85, C9, 74, 2A, 8B, 83, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 1C 7CA7F506 5 Bytes [ B6, EC, 77, 9E, 7C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 22 7CA7F50C 26 Bytes CALL 7C9F3A7E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 3D 7CA7F527 18 Bytes CALL 7C9F3A81 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 52 7CA7F53C 27 Bytes [ 6A, 00, FF, 75, FC, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoW + 6F 7CA7F559 54 Bytes [ A1, 08, C5, BC, 7C, 53, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 11 7CA7FA04 32 Bytes [ FF, F3, AB, 68, 08, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 32 7CA7FA25 6 Bytes [ FF, 50, E8, 0E, F8, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 39 7CA7FA2C 5 Bytes [ 8D, 85, D8, F7, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconResInfoA + 3F 7CA7FA32 67 Bytes [ 50, FF, 15, AC, 20, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 17 7CA7FA76 35 Bytes [ FF, FF, 15, 78, 20, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 3B 7CA7FA9A 39 Bytes [ C9, C2, 04, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 63 7CA7FAC2 11 Bytes [ 00, 00, 8D, 85, F4, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 6F 7CA7FACE 25 Bytes [ 15, E0, 19, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExW + 89 7CA7FAE8 38 Bytes [ 15, CC, 20, 9D, 7C, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 20 7CA7FC4A 10 Bytes [ 75, 0C, FF, 75, 10, 53, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 2D 7CA7FC57 24 Bytes [ F8, 56, FF, 15, 90, 1A, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 48 7CA7FC72 57 Bytes [ 00, 74, 16, FF, B5, EC, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 82 7CA7FCAC 5 Bytes [ 75, 08, E8, 1C, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconExA + 89 7CA7FCB3 88 Bytes [ 5D, C2, 08, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconW + F 7CA7FD28 41 Bytes [ 08, 57, 8B, 7D, 0C, 68, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconW + 39 7CA7FD52 53 Bytes CALL 7CA7F54A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconA + 11 7CA7FD88 56 Bytes [ 5D, C2, 10, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractIconA + 4A 7CA7FDC1 26 Bytes [ FF, 8D, 85, E4, FB, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + 1 7CA7FDDC 13 Bytes [ 45, F8, FF, B5, E0, FB, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + F 7CA7FDEA 163 Bytes [ FF, 33, C0, 40, EB, 05, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + B3 7CA7FE8E 82 Bytes [ 55, 8B, EC, 8B, 45, 14, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!InternalExtractIconListW + 108 7CA7FEE3 41 Bytes [ 8B, FF, 55, 8B, EC, 53, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 28 7CA7FF0D 104 Bytes [ C0, 74, 1B, 8B, 4D, 14, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 91 7CA7FF76 165 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ExtractAssociatedIconA + 137 7CA8001C 17 Bytes [ 00, 2B, D7, 79, 02, F7, DA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 4 7CA8002E 78 Bytes [ CF, 2B, CA, 8B, D1, 0F, AF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 53 7CA8007D 1 Byte [ AF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + 55 7CA8007F 102 Bytes [ 0F, AF, C3, 33, D2, F7, F1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DoEnvironmentSubstA + BC 7CA800E6 150 Bytes [ 7D, 18, 8B, 1D, 10, 11, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + 5D 7CA8017D 57 Bytes [ 45, 1C, FF, 70, 08, FF, D3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + 97 7CA801B7 11 Bytes [ 75, F0, FF, 75, 08, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + A3 7CA801C3 26 Bytes [ 75, EC, FF, D6, FF, 75, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + BE 7CA801DE 51 Bytes [ 50, 6A, 01, 6A, 00, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDiskFreeSpaceA + F2 7CA80212 116 Bytes [ D8, 53, FF, 75, 08, FF, D7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHelpShortcuts_RunDLL + 3C 7CA8032B 78 Bytes [ 08, FF, 15, 24, 12, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 20 7CA8037A 181 Bytes [ 76, 22, 6A, 00, FF, 75, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + D6 7CA80430 63 Bytes [ 00, 3B, 4D, 10, 74, 1A, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 116 7CA80470 148 Bytes [ 0C, 74, 0B, 46, 83, C0, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 1AB 7CA80505 18 Bytes [ FF, 8B, 4D, 18, 33, FF, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHObjectProperties + 1BE 7CA80518 34 Bytes [ 51, BE, 04, 01, 00, 00, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 16 7CA80763 81 Bytes [ 8B, 8D, C4, FD, FF, FF, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 68 7CA807B5 6 Bytes [ 00, 66, 83, BD, CE, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 6F 7CA807BC 21 Bytes [ FF, 01, 66, 89, 9D, CC, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 85 7CA807D2 9 Bytes [ 6B, C0, 0E, 83, C0, 06, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellMessageBoxA + 8F 7CA807DC 16 Bytes [ 15, 48, 19, 9D, 7C, 3B, C3, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + D 7CA80828 65 Bytes [ FF, A5, 83, C0, 06, 66, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 4F 7CA8086A 9 Bytes [ F0, FD, FF, FF, 8B, BD, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 59 7CA80874 67 Bytes [ 8B, 8D, DC, FD, FF, FF, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + 9D 7CA808B8 32 Bytes [ FF, 15, 4C, 19, 9D, 7C, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFlushClipboard + BF 7CA808DA 29 Bytes [ FF, B5, DC, FD, FF, FF, E9, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 14 7CA80F1D 1 Byte [ 66 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 16 7CA80F1F 91 Bytes [ B5, DC, FD, FF, FF, B9, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 72 7CA80F7B 79 Bytes [ DC, FD, FF, FF, 50, 56, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + C2 7CA80FCB 128 Bytes [ 55, 8B, EC, 33, C0, 39, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathIsSlowA + 143 7CA8104C 16 Bytes [ 75, 08, FF, 15, 90, 1F, 9D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 20 7CA81326 3 Bytes [ C0, 74, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 24 7CA8132A 44 Bytes [ 75, 14, 57, FF, 75, 0C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 54 7CA8135A 52 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 8A 7CA81390 4 Bytes [ 50, 6A, 02, 56 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathGetShortPath + 8F 7CA81395 13 Bytes CALL 7C9F7E45 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!IsLFNDriveA + 43 7CA814C5 1 Byte [ 08 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 5 7CA814D1 48 Bytes [ 83, EC, 34, 53, 56, 8B, 35, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 36 7CA81502 21 Bytes [ CC, 50, FF, 75, 0C, 89, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 4C 7CA81518 32 Bytes [ 75, 08, FF, 15, C8, 13, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 6D 7CA81539 38 Bytes [ 6A, 00, 6A, 00, 68, 04, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathQualify + 94 7CA81560 126 Bytes CALL 7CA814CA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 8 7CA818BC 31 Bytes [ 00, 00, 0D, 00, 00, 07, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 28 7CA818DC 95 Bytes [ 7D, 08, 6A, 04, 57, FF, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + 88 7CA8193C 35 Bytes [ FF, 50, 8D, 85, 24, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + AC 7CA81960 58 Bytes [ EB, 03, 83, 26, 00, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PathMakeUniqueName + E7 7CA8199B 25 Bytes [ 15, 84, 1F, 9D, 7C, 8B, 4D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 18 7CA82768 43 Bytes [ 7D, 08, 89, 95, E0, FB, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 44 7CA82794 13 Bytes [ 03, C0, 89, 85, C8, FB, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 52 7CA827A2 42 Bytes [ FF, 2B, C7, 03, C3, D1, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 7D 7CA827CD 9 Bytes JMP 7CA82884 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PickIconDlg + 87 7CA827D7 5 Bytes [ FF, 8D, 85, F4, FD ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + 5B 7CA835CA 10 Bytes [ 15, 0C, 13, 9D, 7C, E9, E1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + 66 7CA835D5 58 Bytes [ 35, C8, 12, 9D, 7C, 6A, 0B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + A1 7CA83610 18 Bytes [ 15, 1C, 11, 9D, 7C, 33, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + B4 7CA83623 8 Bytes [ 76, 18, FF, 15, 18, 11, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHInvokePrinterCommandA + BD 7CA8362C 247 Bytes CALL 7CA39AD3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLL + 28 7CA83724 168 Bytes [ 56, 89, 07, FF, 15, 90, 1A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 4C 7CA837CD 2 Bytes [ 75, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 4F 7CA837D0 3 Bytes [ 45, F4, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 53 7CA837D4 8 Bytes [ 75, F8, FF, 75, FC, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 5C 7CA837DD 8 Bytes [ 75, 08, FF, 75, 18, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PrintersGetCommand_RunDLLW + 66 7CA837E7 64 Bytes [ 75, 2E, FF, D3, 83, F8, 7A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAddFromPropSheetExtArray + 2 7CA83BA1 109 Bytes [ 3C, 00, 00, 00, C7, 85, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 18 7CA83C0F 74 Bytes [ F8, FF, 15, A0, 1A, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 63 7CA83C5A 78 Bytes [ 80, 00, 00, 56, 89, 85, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + B2 7CA83CA9 7 Bytes [ C7, 74, 38, 66, 39, 38, 74 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + BA 7CA83CB1 79 Bytes CALL 7CA23E6B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHReplaceFromPropSheetExtArray + 10B 7CA83D02 32 Bytes CALL 7CACBA26 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 1 7CA83DD1 6 Bytes [ 35, 8C, 1A, 9D, 7C, 53 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 8 7CA83DD8 2 Bytes [ 77, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + B 7CA83DDB 184 Bytes [ D6, 8D, 5C, 00, 02, 8D, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + C4 7CA83E94 84 Bytes [ EC, 56, 57, FF, 75, 08, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreatePropSheetExtArray + 119 7CA83EE9 32 Bytes [ FF, 8B, 45, 0C, BE, 08, 02, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryPoint + 5 7CA83F4A 1 Byte [ FB ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryPoint + 7 7CA83F4C 118 Bytes [ FF, 50, C7, 85, CC, F7, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 10 7CA83FC3 9 Bytes [ B5, C8, F7, FF, FF, 89, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 1A 7CA83FCD 86 Bytes CALL 7CAA134A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 71 7CA84024 6 Bytes [ FF, 50, 8D, 85, DC, F7 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + 78 7CA8402B 66 Bytes CALL 7CA26C4E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DragQueryFile + BB 7CA8406E 2 Bytes [ EC, FB ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 3F 7CA84761 33 Bytes [ FF, 75, FC, FF, 15, 90, 1A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 61 7CA84783 3 Bytes [ 55, 8B, EC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 65 7CA84787 5 Bytes JMP 7CA84641 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 6D 7CA8478F 49 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialogEx + 9F 7CA847C1 60 Bytes CALL 06A847C1
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 3E 7CA8504F 49 Bytes [ 55, 8B, EC, 81, EC, CC, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 70 7CA85081 1 Byte [ 40 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 74 7CA85085 5 Bytes [ 8D, 85, 50, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + 7A 7CA8508B 50 Bytes [ 50, 6A, 09, 33, F6, 56, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RestartDialog + AD 7CA850BE 22 Bytes [ FF, FF, 15, 8C, 1B, 9D, 7C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 28 7CA859F5 112 Bytes [ EB, 90, 66, 83, 7D, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 99 7CA85A66 109 Bytes [ 8B, 75, 10, 83, E6, F0, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 107 7CA85AD4 175 Bytes [ 75, 14, 56, FF, 75, 08, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 1B7 7CA85B84 66 Bytes [ 15, 90, 1A, 9D, 7C, 8B, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenPropSheetW + 1FA 7CA85BC7 21 Bytes [ 15, 64, 13, 9D, 7C, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesW + 47 7CA876B3 20 Bytes [ C6, 8B, 75, 10, 74, 11, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesW + 5C 7CA876C8 209 Bytes [ 50, 10, 53, FF, 15, 68, 1A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + 85 7CA8779A 14 Bytes [ 53, 18, FF, 75, F8, FF, D7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + 94 7CA877A9 45 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CheckEscapesA + C2 7CA877D7 47 Bytes [ 15, 90, 1A, 9D, 7C, 83, 26, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 1 7CA87807 14 Bytes [ 35, 2C, 13, 9D, 7C, 6A, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 11 7CA87817 14 Bytes [ 10, FF, D6, 6A, 00, 50, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 20 7CA87826 28 Bytes [ D6, 85, C0, 5E, 74, 0F, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNW + 3E 7CA87844 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 1 7CA87848 29 Bytes [ EC, 51, 83, 65, FC, 00, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 1F 7CA87866 23 Bytes [ 85, C0, 7C, 20, 8D, 45, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCpyNA + 37 7CA8787E 18 Bytes [ 8B, 45, FC, F7, D8, 1B, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpW + E 7CA87891 30 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpW + 2D 7CA878B0 122 Bytes CALL 7CBAAC2B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpA + 22 7CA8792B 4 Bytes [ EB, 03, 83, 27 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpA + 27 7CA87930 128 Bytes [ 53, 6A, 3C, 8D, 5E, 3C, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIW + 30 7CA879B1 99 Bytes [ AA, 68, C8, 7D, 9E, 7C, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 27 7CA87A15 24 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 40 7CA87A2E 40 Bytes [ 08, 57, 68, 51, 33, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCmpIA + 69 7CA87A57 16 Bytes [ FF, D7, C7, 85, 4C, FA, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCpyW + 2 7CA87A68 96 Bytes [ FF, 0F, BF, 00, 68, 50, A6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrNCpyA + 18 7CA87AC9 62 Bytes [ FF, 74, 48, 8B, 85, 4C, FA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrW + 7 7CA87B08 78 Bytes [ 33, 00, 00, FF, 76, 34, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrW + 56 7CA87B57 78 Bytes [ 06, 43, 83, FB, 0C, 72, E3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 38 7CA87BA6 1 Byte [ 17 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 3A 7CA87BA8 3 Bytes [ B5, 44, FA ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 3E 7CA87BAC 50 Bytes [ FF, 8D, 85, 50, FA, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 71 7CA87BDF 19 Bytes [ 50, 68, 9A, 01, 00, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrA + 85 7CA87BF3 9 Bytes [ 8D, 85, 3C, FA, FF, FF, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 1B 7CA87C4B 56 Bytes [ BE, B8, 00, 00, 00, 01, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 54 7CA87C84 20 Bytes [ F8, FF, 89, 85, 38, FA, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetPathOffsetW + 69 7CA87C99 69 Bytes [ A5, 4C, FA, FF, FF, 00, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirW + 35 7CA87CDF 112 Bytes [ FF, 8B, 9D, 34, FA, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 4 7CA87D50 33 Bytes [ 8E, BC, 00, 00, 00, 66, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 27 7CA87D73 48 Bytes [ D7, 6A, 00, 6A, 00, 68, 86, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 58 7CA87DA4 13 Bytes CALL 7C9F0920 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirA + 66 7CA87DB2 13 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + B 7CA87DC1 24 Bytes CALL 7CA87894 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 24 7CA87DDA 217 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + FE 7CA87EB4 25 Bytes [ 5C, 12, 00, 00, 52, 33, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 118 7CA87ECE 27 Bytes [ FF, 55, 8B, EC, 81, EC, D4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirW + 134 7CA87EEA 7 Bytes [ 15, 44, 1A, 9D, 7C, 83, F8 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirA + 1F 7CA87FB8 29 Bytes [ A1, 08, C5, BC, 7C, 53, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirA + 3D 7CA87FD6 49 Bytes [ 85, C0, 0F, 85, CF, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetCurDrive + 16 7CA88008 75 Bytes [ FF, 89, 85, C4, FE, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheSetCurDrive + 3C 7CA88054 22 Bytes [ FF, 50, 56, FF, 15, F8, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 2 7CA8806B 12 Bytes [ 40, 8D, 85, B8, FE, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + F 7CA88078 16 Bytes [ FF, 10, 20, 9E, 7C, 89, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 20 7CA88089 34 Bytes [ 85, F4, FE, FF, FF, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 43 7CA880AC 26 Bytes [ 05, B8, 05, 00, 07, 80, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathA + 5E 7CA880C7 23 Bytes [ FF, 55, 8B, EC, 51, 8D, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 64 7CA8817F 47 Bytes [ FF, 50, FF, 15, 8C, 1A, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 95 7CA881B0 3 Bytes [ B5, 9C, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + 99 7CA881B4 22 Bytes CALL 7C9F3900 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheFullPathW + B1 7CA881CC 1 Byte [ 04 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 7 7CA881DA 1 Byte [ 04 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 10 7CA881E3 1 Byte [ 56 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 12 7CA881E5 8 Bytes [ 75, 0C, 68, 00, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 1B 7CA881EE 11 Bytes [ FC, 8D, 85, FC, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheGetDirExW + 27 7CA881FA 5 Bytes [ 35, 64, C5, BC, 7C ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 16 7CA882E6 103 Bytes [ 75, 1C, 0F, B7, 45, 10, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 7E 7CA8834E 5 Bytes [ FF, 0F, 84, 15, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 84 7CA88354 19 Bytes [ 00, 56, 8B, 75, 10, 3B, F2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + 98 7CA88368 48 Bytes [ 00, 00, 81, FE, C7, 04, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExW + C9 7CA88399 11 Bytes [ FF, BF, 0C, 03, 00, 00, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 5 7CA88558 54 Bytes [ 5D, EB, AD, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 3C 7CA8858F 38 Bytes [ 85, C0, 0F, 85, 86, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 63 7CA885B6 5 Bytes [ 01, 00, 00, 00, 57 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 69 7CA885BC 167 Bytes [ 75, 0C, FF, 15, 8C, 1A, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheChangeDirExA + 111 7CA88664 59 Bytes [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 25 7CA896CB 9 Bytes [ 50, FF, 36, 66, 89, BD, F0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 2F 7CA896D5 2 Bytes [ 66, C7 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 32 7CA896D8 2 Bytes [ F2, EF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 36 7CA896DC 82 Bytes [ 00, 10, FF, 15, CC, 10, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RegenerateUserEnvironment + 89 7CA8972F 34 Bytes [ D7, 85, C0, 74, 13, 68, B0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + 5 7CA89AD7 7 Bytes [ 00, 83, BD, F0, FD, FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + D 7CA89ADF 22 Bytes [ 74, 7C, C6, 83, FF, 07, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + 24 7CA89AF6 153 Bytes [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + BE 7CA89B90 13 Bytes [ 00, 00, FF, B5, E0, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CallCPLEntry16 + CC 7CA89B9E 28 Bytes [ FF, D6, 85, C0, 0F, 84, 30, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 1 7CA8EF3A 95 Bytes CALL 7C9F091C C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 61 7CA8EF9A 143 Bytes [ 50, 89, 9D, C0, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + F2 7CA8F02B 72 Bytes [ FF, B5, D0, FD, FF, FF, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 13B 7CA8F074 34 Bytes [ 00, FF, 15, 20, 1A, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_CloseProperties + 15E 7CA8F097 11 Bytes [ B0, FD, FF, FF, 50, 53, 68, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 25 7CA8F67C 79 Bytes [ 8B, C6, 5E, 5D, C2, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 75 7CA8F6CC 4 Bytes [ 57, 56, E8, 51 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 7B 7CA8F6D2 19 Bytes [ FF, 8B, F0, 3B, F7, 75, D1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + 8F 7CA8F6E6 81 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_GetProperties + E1 7CA8F738 26 Bytes [ 55, 8B, EC, 83, 7D, 0C, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 65 7CA8FF3B 161 Bytes [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 107 7CA8FFDD 31 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 127 7CA8FFFD 49 Bytes [ 3B, FB, 0F, 9C, C1, 33, D2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 159 7CA9002F 72 Bytes [ 15, 84, 1A, 9D, 7C, EB, 1F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_SetProperties + 1A2 7CA90078 42 Bytes [ FF, FF, 8B, 46, 1C, 66, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 11B 7CA904EF 3 Bytes [ 15, 5C, 20 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 11F 7CA904F3 34 Bytes [ 7C, 85, C0, 74, 10, 83, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 143 7CA90517 34 Bytes [ C9, C3, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 166 7CA9053A 11 Bytes [ 51, 8D, 8D, EC, FB, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!PifMgr_OpenProperties + 172 7CA90546 18 Bytes [ 00, 53, 33, FF, 89, 45, FC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesW + 6 7CA9889B 81 Bytes [ 4D, B8, 8B, 40, 04, C1, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 1C 7CA988ED 9 Bytes [ 75, B0, 89, 75, B4, FF, D3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 26 7CA988F7 84 Bytes [ 21, 8B, 45, AC, 8B, 48, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheRemoveQuotesA + 7B 7CA9894C 96 Bytes [ 89, 48, 22, 8D, 45, B4, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 25 7CA989AD 35 Bytes [ 75, B0, C7, 45, B4, 40, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 49 7CA989D1 27 Bytes [ 83, 60, 02, 00, 6A, 04, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 65 7CA989ED 7 Bytes [ 75, B4, FF, D3, 85, C0, 75 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 6D 7CA989F5 172 Bytes [ 8B, 45, AC, 8B, 40, 04, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathW + 11A 7CA98AA2 60 Bytes [ C9, C2, 04, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + 11 7CA98B4C 147 Bytes [ 56, 8B, 35, B0, 1A, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + A5 7CA98BE0 35 Bytes [ D6, 8B, 47, 04, 8B, 40, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + C9 7CA98C04 40 Bytes [ 45, B8, 8D, 45, B8, 50, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + F2 7CA98C2D 10 Bytes [ 6A, 00, 68, 90, 1B, 9E, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheShortenPathA + FD 7CA98C38 6 Bytes [ 4D, B8, FF, D6, 8B, 47 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + 16 7CA98F05 17 Bytes [ 00, 80, 80, 80, 00, 8B, 42, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + 28 7CA98F17 128 Bytes [ 8B, 42, 04, C7, 80, B4, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + A9 7CA98F98 9 Bytes [ EC, 20, FF, 75, 0C, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + B4 7CA98FA3 2 Bytes [ D0, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SheConvertPathW + B9 7CA98FA8 61 Bytes [ 45, 08, 83, 65, F0, 00, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 10 7CA9A9B0 40 Bytes [ 50, FF, 15, 5C, 13, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 39 7CA9A9D9 1 Byte [ 6A ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 3B 7CA9A9DB 33 Bytes [ FF, 15, 2C, 13, 9D, 7C, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + 5D 7CA9A9FD 70 Bytes [ 15, 54, 13, 9D, 7C, EB, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLL + A4 7CA9AA44 43 Bytes [ 76, 10, FF, 15, E0, 12, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 16 7CA9AA70 16 Bytes [ 10, 8D, 8E, 24, 02, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 27 7CA9AA81 62 Bytes [ D7, F7, D8, 1B, C0, 40, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 66 7CA9AAC0 30 Bytes [ 75, 08, 6A, 00, FF, 35, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + 86 7CA9AAE0 31 Bytes [ 68, 8C, CE, 9D, 7C, BB, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!OpenAs_RunDLLW + A6 7CA9AB00 11 Bytes [ 0D, 64, C5, BC, 7C, 89, 4D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 12 7CA9BA16 24 Bytes [ B5, E0, FD, FF, FF, 89, BD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 2B 7CA9BA2F 12 Bytes [ FF, 57, FF, 15, 90, 1A, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 39 7CA9BA3D 6 Bytes [ 00, 5F, 5E, 5B, 7C, 06 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 40 7CA9BA44 38 Bytes [ 15, E4, C0, BC, 7C, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Activate_RunDLL + 67 7CA9BA6B 26 Bytes [ 8B, 5D, 08, 56, 8B, 75, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 1F 7CA9EEEC 5 Bytes [ 53, 8D, 95, EC, DC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 25 7CA9EEF2 29 Bytes [ FF, 52, FF, B5, E0, DC, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 43 7CA9EF10 10 Bytes [ 83, 3E, 00, 75, A2, 8B, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 4E 7CA9EF1B 22 Bytes [ 8B, 08, 50, FF, 51, 08, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHIsFileAvailableOffline + 65 7CA9EF32 45 Bytes [ C9, C2, 10, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + 36 7CA9F2ED 132 Bytes [ C2, 08, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + BC 7CA9F373 5 Bytes [ FF, 75, 0C, 6A, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + C2 7CA9F379 6 Bytes [ 75, 08, E8, 28, 1D, F9 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + C9 7CA9F380 15 Bytes [ 8B, F0, 8B, 45, 08, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnumerateUnreadMailAccountsW + D9 7CA9F390 60 Bytes [ C6, 5E, 5D, C2, 0C, 00, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 21 7CA9F67C 100 Bytes [ 14, 8B, C1, 75, 05, 39, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 86 7CA9F6E1 2 Bytes [ 85, D7 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 8B 7CA9F6E6 13 Bytes [ 8D, 85, FC, FB, FF, FF, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + 99 7CA9F6F4 21 Bytes JMP 7CA9F7BA C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetAttributesFromDataObject + AF 7CA9F70A 66 Bytes [ 11, B5, AC, FB, FF, FF, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA 7CAA17AE 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + 4 7CAA17B2 156 Bytes [ FF, 55, 8B, EC, 56, 8B, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + A1 7CAA184F 47 Bytes [ 15, 8C, 1A, 9D, 7C, 8B, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + D1 7CAA187F 150 Bytes [ 08, 50, FF, 51, 04, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPathPrepareForWriteA + 168 7CAA1916 33 Bytes [ 89, 45, FC, 8B, 45, 10, 89, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 1C 7CAA1B03 39 Bytes [ F8, 01, 00, 00, 00, E8, 91, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 44 7CAA1B2B 2 Bytes [ 84, 63 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 49 7CAA1B30 28 Bytes [ 8B, 0F, 80, E1, 01, F6, D9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 66 7CAA1B4D 36 Bytes [ 51, 53, 6A, 00, 68, 6C, 78, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetUnreadMailCountW + 8B 7CAA1B72 29 Bytes [ 75, FC, FF, D6, 8B, 07, F7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 11 7CAA1D0C 199 Bytes [ EC, 56, 33, F6, 39, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + D9 7CAA1DD4 10 Bytes CALL D026BAEB
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + E4 7CAA1DDF 79 Bytes [ FF, 50, 8D, 85, FC, DF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 135 7CAA1E30 11 Bytes [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHSetUnreadMailCountW + 141 7CAA1E3C 35 Bytes [ 8D, 85, F4, FD, FF, FF, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 27 7CAA21AA 54 Bytes [ 8B, 45, 18, 57, 89, 85, E0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 5E 7CAA21E1 12 Bytes [ FF, 89, BD, BC, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 6B 7CAA21EE 11 Bytes [ 89, BD, C4, FD, FF, FF, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 77 7CAA21FA 16 Bytes [ 89, 85, CC, FD, FF, FF, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetShellStyleHInstance + 88 7CAA220B 38 Bytes [ FF, 74, 51, 53, 68, 04, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 2A 7CAA50A7 38 Bytes [ D3, 6A, 01, 68, 82, 70, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 51 7CAA50CE 11 Bytes [ D3, 68, B4, 43, 9D, 7C, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 5D 7CAA50DA 10 Bytes [ 76, 30, FF, D7, 50, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + 68 7CAA50E5 104 Bytes [ 83, 66, 04, 00, 5F, C7, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFormatDrive + D1 7CAA514E 8 Bytes [ 15, D4, 12, 9D, 7C, 8B, F8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 2 7CAA57C9 37 Bytes [ 51, 05, 20, 70, 00, 00, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 28 7CAA57EF 12 Bytes JMP 7CAA5888 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 35 7CAA57FC 28 Bytes CALL 7CAA4C1E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + 54 7CAA581B 100 Bytes [ FF, B5, D0, FD, FF, FF, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!AppCompat_RunDLLW + B9 7CAA5880 20 Bytes [ 0F, AF, 85, D8, FD, FF, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create + 36 7CAA6F5B 143 Bytes [ 15, 9D, 7C, 6A, 00, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 27 7CAA6FEB 22 Bytes [ 35, EC, 14, 9D, 7C, 6A, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 3F 7CAA7003 1 Byte [ 08 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 41 7CAA7005 48 Bytes [ D6, 83, C7, FD, 6A, 00, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 72 7CAA7036 21 Bytes [ 15, 04, 13, 9D, 7C, 8B, 1D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!CDefFolderMenu_Create2 + 88 7CAA704C 89 Bytes [ FF, FF, 8B, F8, 85, FF, 7C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll 7CAB22D7 22 Bytes [ 1A, 9D, 7C, 33, C0, 5E, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 17 7CAB22EE 29 Bytes [ 85, C0, 74, 14, 81, 78, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 35 7CAB230C 6 Bytes [ 90, 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 3C 7CAB2313 30 Bytes [ 55, 8B, EC, 53, 56, 8B, 35, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_AutoScroll + 5B 7CAB2332 142 Bytes [ 00, 57, FF, D6, 53, 68, 2E, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 1 7CABB59D 32 Bytes [ 55, F8, D1, F8, 03, D1, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 22 7CABB5BE 45 Bytes [ CE, 2B, C8, 89, 4D, FC, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragEnterEx + 50 7CABB5EC 78 Bytes [ FF, 39, 7D, 0C, 8B, F0, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 6 7CABB63B 25 Bytes [ FF, 15, 34, 12, 9D, 7C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 21 7CABB656 75 Bytes CALL 7CA82C5A C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 6D 7CABB6A2 9 Bytes [ D3, FF, 75, E4, FF, 75, F4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_SetDragImage + 77 7CABB6AC 60 Bytes [ 75, F4, FF, 15, 44, 12, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragLeave + 19 7CABB6E9 21 Bytes [ FF, 47, 8B, C7, 5F, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DAD_DragLeave + 31 7CABB701 51 Bytes [ 8D, 45, 0C, 50, 8D, 45, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 4 7CABB735 10 Bytes [ 35, 40, 12, 9D, 7C, 74, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + F 7CABB740 83 Bytes [ D6, 83, 7D, 0C, 00, 74, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 63 7CABB794 8 Bytes [ EC, 53, 57, 8B, 7D, 08, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 6C 7CABB79D 31 Bytes [ 3B, F8, 8B, D9, 75, 0C, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDoDragDrop + 8C 7CABB7BD 77 Bytes [ 86, 1C, D6, 9D, 7C, FF, B6, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 3B 7CABE7F7 67 Bytes [ FF, 6A, 50, 50, FF, D6, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 80 7CABE83C 4 Bytes [ B5, B8, FE, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + 86 7CABE842 47 Bytes [ 15, A0, 1A, 9D, 7C, 33, DB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + B6 7CABE872 1 Byte [ 73 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!DllInstall + B8 7CABE874 25 Bytes [ 70, 00, 31, 00, 72, 00, 65, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 56 7CAC19F0 25 Bytes [ 33, C0, 83, FB, 02, 0F, 95, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 70 7CAC1A0A 318 Bytes [ 57, FF, 15, 20, 13, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1B0 7CAC1B4A 58 Bytes [ 50, 8D, 85, D4, F5, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1EB 7CAC1B85 3 Bytes [ 85, EC, FB ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHDefExtractIconA + 1F0 7CAC1B8A 6 Bytes [ 50, 8D, 85, DC, F7, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 1 7CAC1F3A 68 Bytes [ 45, 14, 68, F0, 0F, AC, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 46 7CAC1F7F 47 Bytes JMP E70A949F
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + 76 7CAC1FAF 43 Bytes [ 15, 2C, 13, 9D, 7C, EB, 2C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + A2 7CAC1FDB 57 Bytes [ 10, FF, 15, E4, 13, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHValidateUNC + DC 7CAC2015 57 Bytes [ 12, 00, 00, 5B, 38, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SignalFileOpen + C9 7CAC27B2 14 Bytes [ 15, A0, 1A, 9D, 7C, 89, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SignalFileOpen + D8 7CAC27C1 16 Bytes [ 80, 6A, 40, 8D, 85, 64, FE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 2 7CAC27D2 53 Bytes [ B0, 60, 9D, 9E, 7C, C7, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 38 7CAC2808 14 Bytes [ 85, 54, FC, FF, FF, 50, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 47 7CAC2817 21 Bytes [ 6A, 02, 6A, 00, 8D, 85, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExA + 5D 7CAC282D 164 Bytes [ B4, 00, 00, 00, 68, A0, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteExW + 59 7CAC28D2 90 Bytes [ FE, FF, FF, EB, DB, 8D, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + B 7CAC292D 20 Bytes [ FF, 50, 8D, 85, 5C, FC, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + 20 7CAC2942 2 Bytes [ 50, 53 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteA + 23 7CAC2945 41 Bytes [ 15, BC, 1F, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteW + 1A 7CAC296F 10 Bytes CALL 7CA9EA3F C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!RealShellExecuteW + 25 7CAC297A 14 Bytes [ 83, FE, 50, 0F, 82, 78, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + 1 7CAC2989 108 Bytes [ 4D, FC, 5F, 5E, 5B, E8, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + 6E 7CAC29F6 96 Bytes [ FF, 55, 8B, EC, 8D, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + CF 7CAC2A57 7 Bytes [ F8, 66, 8B, 07, 66, 85, C0 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + D7 7CAC2A5F 21 Bytes JMP 7CAC2B4B C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExecuteW + ED 7CAC2A75 67 Bytes [ 74, 02, 47, 47, 56, 8B, 35, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 27 7CAC3F69 6 Bytes [ FF, 50, 8D, 85, F4, FD ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 2E 7CAC3F70 9 Bytes [ FF, 50, 53, FF, 15, 34, 13, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 38 7CAC3F7A 78 Bytes [ 4D, FC, 5F, 5E, 5B, E8, 9C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 87 7CAC3FC9 6 Bytes [ 66, 89, 85, E4, F0, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!GetFileNameFromBrowse + 8E 7CAC3FD0 5 Bytes [ 33, C0, 53, 56, 57 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 11 7CAC4331 67 Bytes [ 50, 8D, 45, FC, 2B, 85, 78, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 55 7CAC4375 36 Bytes [ 15, 34, 21, 9D, 7C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 7B 7CAC439B 14 Bytes [ 3D, 3C, 20, 9D, 7C, 6A, 5C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + 8A 7CAC43AA 28 Bytes [ D7, 85, C0, 75, 0F, 6A, 2F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILAppendID + A7 7CAC43C7 41 Bytes [ D7, 50, 8D, 85, EC, FB, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 9 7CAC4588 26 Bytes [ 50, FF, 51, 28, EB, 06, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 24 7CAC45A3 59 Bytes [ 50, 56, FF, B5, 4C, F1, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 60 7CAC45DF 16 Bytes [ 85, 50, F1, FF, FF, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 71 7CAC45F0 16 Bytes [ FF, 50, FF, B5, 6C, F1, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ILCreateFromPathA + 82 7CAC4601 61 Bytes [ B5, 68, F1, FF, FF, E8, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 29 7CAC66ED 2 Bytes [ 55, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 2C 7CAC66F0 46 Bytes [ 4D, DC, 5B, F6, 46, 20, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 5B 7CAC671F 2 Bytes [ 35, F9 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 5E 7CAC6722 40 Bytes [ FF, 85, C0, 8B, 4D, DC, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetFolderPathAndSubDirA + 87 7CAC674B 25 Bytes [ 45, D8, 33, D2, 39, 55, 08, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 46 7CAC7A33 20 Bytes [ 15, AC, 1A, 9D, 7C, FF, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 5C 7CAC7A49 66 Bytes [ 00, 80, 0F, 85, 94, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + 9F 7CAC7A8C 69 Bytes [ FF, 50, 8B, 45, 08, 33, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + E5 7CAC7AD2 12 Bytes [ D3, 89, 85, D4, FB, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHHandleUpdateImage + F2 7CAC7ADF 16 Bytes [ FF, 15, A0, 1A, 9D, 7C, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 15 7CAC7FC9 41 Bytes [ 76, 08, 57, FF, B5, F0, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 3F 7CAC7FF3 16 Bytes [ FF, 50, 68, 00, 80, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 50 7CAC8004 14 Bytes [ 0D, FF, B5, EC, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 5F 7CAC8013 1 Byte [ 76 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHChangeNotifySuspendResume + 61 7CAC8015 4 Bytes [ FF, B5, F0, FD ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 29 7CAC80BE 14 Bytes CALL 7C9F9620 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 38 7CAC80CD 5 Bytes [ 8D, 85, F4, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 3E 7CAC80D3 33 Bytes [ 50, FF, 15, 6C, 1F, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 60 7CAC80F5 17 Bytes [ 15, 7C, 20, 9D, 7C, 39, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageW + 72 7CAC8107 205 Bytes [ 15, 8C, 1A, 9D, 7C, 8B, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 1 7CAC81D5 72 Bytes [ 45, 10, 89, 85, EC, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 4A 7CAC821E 24 Bytes [ 00, F6, 46, 11, 01, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + 63 7CAC8237 60 Bytes [ 40, 00, 00, 6A, 00, 56, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + A0 7CAC8274 16 Bytes CALL 7CAC7F52 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHUpdateImageA + B1 7CAC8285 38 Bytes [ FF, D7, 50, 6A, 40, 68, 32, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 15 7CACF1E1 61 Bytes [ EB, C4, C7, 45, FC, 0E, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 53 7CACF21F 5 Bytes [ 57, 8D, 45, FC, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 59 7CACF225 26 Bytes CALL 7CACB6FC C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 74 7CACF240 146 Bytes [ FF, 8B, F0, 85, F6, 7C, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetDataFromIDListA + 107 7CACF2D3 136 Bytes [ 74, 08, 2B, C1, 0F, 85, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 79 7CACF4C4 23 Bytes [ 51, 0C, 8B, D8, 3B, DE, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 91 7CACF4DC 107 Bytes [ 75, 0C, FF, 15, 88, 1E, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + FD 7CACF548 6 Bytes JMP 7CACF63E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 104 7CACF54F 61 Bytes [ 34, 8D, A0, AF, A6, 7C, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetNewLinkInfo + 142 7CACF58D 8 Bytes [ F9, 0A, 0F, 8C, A9, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHOpenFolderAndSelectItems + 7B 7CACF885 28 Bytes [ 7C, 0E, 8B, 4D, FC, F7, D9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem 7CACF8A2 7 Bytes [ 90, 90, 90, 90, 8B, FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 8 7CACF8AA 29 Bytes [ EC, 51, 83, 65, FC, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 26 7CACF8C8 2 Bytes [ 4D, FC ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 29 7CACF8CB 44 Bytes [ D9, 1B, C9, 83, E1, FE, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellItem + 56 7CACF8F8 47 Bytes [ 75, 08, 6A, 77, 6A, 06, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 9 7CACFA17 18 Bytes [ 59, 8B, 55, 14, 89, 0A, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 1C 7CACFA2A 74 Bytes [ EC, 51, 83, 65, FC, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + 67 7CACFA75 66 Bytes [ 75, 0C, FF, 75, 08, 6A, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + AA 7CACFAB8 79 Bytes [ 75, 08, 6A, 02, 6A, 0A, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateFileExtractIconW + FA 7CACFB08 63 Bytes [ 4D, FC, F7, D9, 1B, C9, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 14 7CAD0C5F 114 Bytes [ 8D, 85, 54, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 87 7CAD0CD2 4 Bytes [ 8D, 85, 4C, FB ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + 8C 7CAD0CD7 36 Bytes [ FF, 50, FF, 15, D8, 19, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + B1 7CAD0CFC 76 Bytes [ FF, 5F, 5E, 8B, 4D, FC, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHAppBarMessage + FE 7CAD0D49 5 Bytes [ FF, 89, 9D, D0, F9 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHEnableServiceObject + 2 7CAD0DBD 100 Bytes [ D6, 8D, 85, F4, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 30 7CAD0E22 16 Bytes [ FF, 50, FF, 15, 60, 1F, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 41 7CAD0E33 24 Bytes [ 0F, 84, 33, 01, 00, 00, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 5A 7CAD0E4C 12 Bytes [ FF, 50, FF, B5, CC, F9, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 67 7CAD0E59 50 Bytes [ FF, 50, FF, D3, FF, B5, D0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetInstanceExplorer + 9B 7CAD0E8D 15 Bytes CALL 7CA1EA16 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 17 7CAD3DA2 94 Bytes [ C1, C7, 00, B0, 27, 9E, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 76 7CAD3E01 12 Bytes [ 50, 68, 00, 80, 00, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + 83 7CAD3E0E 78 Bytes [ B5, F0, FD, FF, FF, E8, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + D3 7CAD3E5E 4 Bytes [ 08, 50, FF, 51 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolderW + D8 7CAD3E63 142 Bytes [ 8B, 4D, FC, 33, C0, 85, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 6D 7CAD3EF2 11 Bytes CALL 7CA0E665 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 79 7CAD3EFE 18 Bytes [ 1D, D4, 12, 9D, 7C, 89, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 8C 7CAD3F11 12 Bytes [ 50, 68, 44, 37, 00, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + 99 7CAD3F1E 25 Bytes [ 15, E4, 12, 9D, 7C, 83, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHBrowseForFolder + B3 7CAD3F38 143 Bytes [ 15, 54, 13, 9D, 7C, FF, 37, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WOWShellExecute + 2F 7CAD5268 78 Bytes [ 59, 8B, C6, 5E, 5D, C2, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!WOWShellExecute + 7E 7CAD52B7 315 Bytes [ 51, 30, 8B, 46, 10, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLL + 24 7CAD53F3 126 Bytes [ EC, 10, 00, 00, 00, E8, F1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 3D 7CAD5472 12 Bytes [ 50, 0C, 8B, F0, 85, F6, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 4A 7CAD547F 30 Bytes CALL 7CAD5121 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 69 7CAD549E 2 Bytes [ 08, 53 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 6C 7CAD54A1 4 Bytes [ 5D, 18, 53, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!ShellExec_RunDLLW + 71 7CAD54A6 17 Bytes [ 14, 6A, 00, 57, 50, FF, 51, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 23 7CAD6018 41 Bytes [ 75, FC, FF, 15, 58, 19, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 4D 7CAD6042 46 Bytes [ 15, 68, 13, 9D, 7C, 56, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 7C 7CAD6071 15 Bytes [ 00, 75, 0B, 53, FF, 15, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + 8D 7CAD6082 22 Bytes [ FF, 75, 10, 68, 13, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateProcessAsUserW + A4 7CAD6099 328 Bytes [ 7D, 08, 00, 74, 30, 6A, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + 28 7CAD76F3 79 Bytes CALL 7CA31BC1 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + 78 7CAD7743 48 Bytes [ FF, FF, 15, A0, 1A, 9D, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + AA 7CAD7775 24 Bytes [ 45, FC, 8B, 45, 0C, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + C3 7CAD778E 14 Bytes [ FD, FF, FF, 8D, 5E, F0, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHShellFolderView_Message + D2 7CAD779D 48 Bytes [ 89, BD, DC, FD, FF, FF, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 2D 7CAD7BA0 9 Bytes [ F4, F9, FF, FF, 50, E8, A9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 37 7CAD7BAA 10 Bytes [ F7, D8, 1B, C0, 83, E0, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 42 7CAD7BB5 40 Bytes [ 00, 50, FF, 35, 64, C5, BC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 6B 7CAD7BDE 9 Bytes [ 83, C4, 10, EB, 31, 8B, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateShellFolderViewEx + 75 7CAD7BE8 18 Bytes [ FF, BB, 00, 01, 00, 00, 53, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 2 7CAD98C0 93 Bytes [ 5E, 5D, C2, 08, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 60 7CAD991E 45 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + 8E 7CAD994C 44 Bytes CALL 7C9F3900 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + BB 7CAD9979 36 Bytes [ 10, 89, 06, 74, 46, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFind_InitMenuPopup + E0 7CAD999E 256 Bytes [ FF, FF, 85, C0, 74, 0A, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 19 7CADAF35 27 Bytes [ 76, 20, 8B, 06, 57, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 35 7CADAF51 7 Bytes [ 51, 1C, 85, C0, 7C, E7, 33 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + 3D 7CADAF59 171 Bytes [ 39, 7D, F8, 7E, E0, 8B, 46, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + EA 7CADB006 6 Bytes [ 0F, 84, C3, 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHFindFiles + F1 7CADB00D 11 Bytes [ 8D, F0, FD, FF, FF, 3B, BD, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 2 7CADE6DC 122 Bytes [ 51, 40, 8B, F0, 3B, F7, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 7D 7CADE757 10 Bytes [ 5C, FF, FF, FF, 3B, F7, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 89 7CADE763 8 Bytes [ EB, 07, 66, 8B, 85, 5C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + 92 7CADE76C 29 Bytes [ 68, 00, 04, 00, 00, 57, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHStartNetConnectionDialogW + B0 7CADE78A 10 Bytes [ 1B, C0, 23, C1, 50, 68, A0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + 2 7CAE04BC 37 Bytes [ 75, 10, 8B, 08, FF, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + 28 7CAE04E2 130 Bytes CALL 7CA086B5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexW + AB 7CAE0565 112 Bytes [ 39, 5D, 14, 74, 0B, 6A, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 44 7CAE05D6 4 Bytes [ 75, 0C, 83, C1 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 49 7CAE05DB 90 Bytes CALL 7CA091E5 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + A4 7CAE0636 77 Bytes CALL 7CA091E3 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + F2 7CAE0684 51 Bytes [ FF, 8B, 08, 50, FF, 51, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHGetIconOverlayIndexA + 126 7CAE06B8 26 Bytes [ 08, 57, 89, 8D, EC, FD, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 4 7CAE1106 1 Byte [ F0 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 7 7CAE1109 108 Bytes [ 0C, 8B, 08, 50, FF, 51, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 74 7CAE1176 129 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + F6 7CAE11F8 19 Bytes [ 38, 85, FF, 89, BD, C4, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgCreate + 10A 7CAE120C 82 Bytes [ FF, 15, 68, AF, 9F, 7C, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + 83 7CAE1E58 22 Bytes [ FF, 50, C7, 85, A0, FB, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + 9A 7CAE1E6F 7 Bytes [ FF, 50, 8D, 85, F4, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + A2 7CAE1E77 27 Bytes [ 50, FF, D6, 8D, 85, A4, FB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + BE 7CAE1E93 9 Bytes [ 15, 50, 1A, 9D, 7C, 83, BD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHPropStgWriteMultiple + C8 7CAE1E9D 23 Bytes [ FF, 00, 74, 16, 8D, 85, F4, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 2E 7CAE2AD9 22 Bytes [ C9, C2, 14, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 45 7CAE2AF0 14 Bytes [ 75, 0C, 66, 83, 27, 00, BE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 54 7CAE2AFF 25 Bytes [ FF, 85, C0, 74, 21, 33, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + 6E 7CAE2B19 89 Bytes [ 40, 08, FF, 75, 1C, 57, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLimitInputEdit + C8 7CAE2B73 75 Bytes [ 57, FF, 75, 10, BF, 05, 40, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 36 7CAE2F06 32 Bytes CALL 7CAE2EB2 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 57 7CAE2F27 2 Bytes [ 55, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 5A 7CAE2F2A 7 Bytes [ 51, 53, 56, 57, 8B, F1, 33 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 62 7CAE2F32 39 Bytes [ F6, 46, 08, 02, 0F, 84, A1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHMultiFileProperties + 8B 7CAE2F5B 2 Bytes [ 94, 17 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 4F 7CAE36C6 14 Bytes [ 33, C0, EB, 51, FF, 75, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 5E 7CAE36D5 13 Bytes CALL 7CAE326E C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 6C 7CAE36E3 7 Bytes [ 75, 18, 68, 7D, 26, AE, 7C ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 74 7CAE36EB 3 Bytes [ 75, 08, E8 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHLoadNonloadedIconOverlayIdentifiers + 78 7CAE36EF 13 Bytes [ 82, 0C, 00, 8B, 4D, 1C, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 18 7CB0DE34 8 Bytes [ 90, 90, 90, 90, 38, 36, 9D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 21 7CB0DE3D 22 Bytes [ 43, 9D, 7C, 63, 7A, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 38 7CB0DE54 1 Byte [ FE ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 3A 7CB0DE56 50 Bytes [ 00, 00, 5B, CD, B0, 7C, 23, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!FindExeDlgProc + 6F 7CB0DE8B 5 Bytes [ 90, 90, 8B, FF, 53 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + 4B 7CB68ECB 26 Bytes CALL 7CB669D2 C:\WINDOWS\system32\SHELL32.dll (DLL comune della shell di Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + 66 7CB68EE6 118 Bytes [ D3, 8B, 45, F8, F6, 00, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + DD 7CB68F5D 11 Bytes [ 75, 19, 68, 62, 63, B6, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + E9 7CB68F69 3 Bytes [ 6A, 0A, 6A ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!Options_RunDLLW + ED 7CB68F6D 43 Bytes [ FF, 15, 8C, 13, 9D, 7C, A3, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 1 7CB6AE6B 94 Bytes [ D9, 74, 02, 89, 30, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 60 7CB6AECA 16 Bytes [ 51, 0C, 8B, 45, FC, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + 71 7CB6AEDB 51 Bytes [ 51, 0C, FF, 77, 04, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + A6 7CB6AF10 12 Bytes [ 8B, 45, EC, 8B, 08, 8D, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!SHCreateLocalServerRunDll + B4 7CB6AF1E 47 Bytes [ 50, FF, 11, 8B, 45, F4, 3B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIA + 1 7CBA9353 3 Bytes [ 15, CC, 16 ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIA + 6 7CBA9358 11 Bytes [ 8B, C6, 5F, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrCmpNIW + 9 7CBA9366 56 Bytes [ 8B, FF, 55, 8B, EC, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrRStrIA 7CBA939F 54 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + B 7CBA93D6 132 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + 90 7CBA945B 10 Bytes [ 50, 57, 68, 17, 04, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + 9B 7CBA9466 32 Bytes [ D3, F6, 85, ED, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + BC 7CBA9487 21 Bytes [ D7, 83, F8, FF, 74, 3D, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] SHELL32.dll!StrStrW + D2 7CBA949D 32 Bytes [ 50, 0F, B7, 85, F4, FD, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA04 774B1931 51 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA3F 774B196C 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA46 774B1973 3 Bytes [ 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA4F 774B197C 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WdtpInterfacePointer_UserFree + FFEDCA56 774B1983 3 Bytes [ 00, 00, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + B5 774CD0F5 10 Bytes [ 43, 6F, 6E, 76, 65, 72, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + C0 774CD100 35 Bytes [ 47, 65, 74, 44, 6F, 63, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + E4 774CD124 19 Bytes [ 6C, 6F, 62, 61, 6C, 46, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + F8 774CD138 37 Bytes [ 47, 65, 74, 48, 47, 6C, 6F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemAlloc + 11E 774CD15E 2 Bytes [ 47, 65 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 52 774CD46B 44 Bytes [ 73, 65, 72, 55, 6E, 6D, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 7F 774CD498 114 Bytes [ 61, 72, 73, 68, 61, 6C, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + F2 774CD50B 155 Bytes [ 6C, 65, 52, 65, 67, 69, 73, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 18E 774CD5A7 219 Bytes [ 6F, 6E, 69, 6B, 65, 72, 52, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsValidInterface + 26A 774CD683 87 Bytes [ 4F, 6C, 65, 43, 72, 65, 61, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMalloc + C5 774CDDAD 94 Bytes [ 55, 74, 47, 65, 74, 44, 76, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 1A 774CDE0C 6 Bytes [ 57, 64, 74, 70, 49, 6E ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 21 774CDE13 71 Bytes [ 65, 72, 66, 61, 63, 65, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 69 774CDE5B 45 Bytes [ 57, 72, 69, 74, 65, 43, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + 97 774CDE89 68 Bytes [ 57, 72, 69, 74, 65, 53, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromGUID2 + DC 774CDECE 17 Bytes [ FF, 55, 8B, EC, 8B, 45, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 6A 774CE594 64 Bytes [ BB, 51, 4D, 77, C3, 4E, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + AB 774CE5D5 111 Bytes [ 90, 90, 90, 90, 8B, FF, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 11B 774CE645 88 Bytes [ 01, 75, 07, 51, FF, 15, 8C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 174 774CE69E 19 Bytes [ EC, 8B, 45, 08, 83, C0, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateBindCtx + 18B 774CE6B5 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 2 774CEDD8 9 Bytes [ 83, C6, 48, 6A, 27, 66, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + C 774CEDE2 4 Bytes [ 66, 83, 66, 02 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 11 774CEDE7 14 Bytes [ 58, 5E, 5D, C2, 0C, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 20 774CEDF6 3 Bytes [ EC, 57, 33 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetState + 24 774CEDFA 17 Bytes [ 39, 7D, 08, 74, 3B, E8, 62, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 52 774CEEDC 4 Bytes [ 84, 5B, BD, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 57 774CEEE1 33 Bytes [ A1, 98, 61, 5D, 77, 57, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 79 774CEF03 4 Bytes [ 15, 80, 12, 4B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetErrorInfo + 7E 774CEF08 63 Bytes [ 89, 7E, 04, 89, 06, FF, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateGuid + 37 774CEF48 14 Bytes [ 00, 0F, 85, 14, 85, 05, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateGuid + 47 774CEF58 3 Bytes [ 8B, FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 1 774CEF5C 2 Bytes [ EC, 56 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 4 774CEF5F 30 Bytes [ 75, 08, 56, 6A, 01, 6A, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 23 774CEF7E 4 Bytes [ 5E, 5D, C2, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 28 774CEF83 18 Bytes [ 90, 90, 90, 90, 90, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeEx + 3B 774CEF96 73 Bytes [ C3, 90, 6D, 52, 55, 77, D7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RegisterDragDrop + 6E 774CF678 71 Bytes [ 98, 85, FF, 0F, 85, E4, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RegisterDragDrop + B6 774CF6C0 68 Bytes [ 51, 6A, 00, FF, 35, 00, 60, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 3B 774CF705 88 Bytes [ CA, 83, E1, 03, F3, A4, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 94 774CF75E 5 Bytes [ 00, 90, 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 9A 774CF764 51 Bytes [ 8B, FF, 55, 8B, EC, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + CE 774CF798 97 Bytes [ 00, 57, 8B, 3C, 81, 85, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitialize + 130 774CF7FA 84 Bytes [ 08, 8B, 4D, 18, 89, 48, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + A 774D0568 35 Bytes [ EC, 8B, 45, 08, 8D, 50, 34, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + 2F 774D058D 2 Bytes [ 57, 33 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + 32 774D0590 56 Bytes [ F6, 46, 28, 01, 89, 7D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + B3 774D0611 5 Bytes [ 75, 0C, 33, DB, E8 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateInstance + B9 774D0617 24 Bytes [ DD, FF, FF, 85, C0, 0F, 84, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + 46 774D2A6A 67 Bytes [ 8B, 45, 14, 8B, C8, 83, E0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + 8A 774D2AAE 28 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + A7 774D2ACB 34 Bytes [ 75, 0C, FF, 75, 08, E8, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + CA 774D2AEE 7 Bytes [ 55, 8B, EC, 51, 83, 65, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitialize + D2 774D2AF6 24 Bytes [ 53, 56, 57, 6A, 2D, FF, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 8 774D2C73 85 Bytes [ 75, 07, 4E, 48, 48, 3B, F1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 5E 774D2CC9 41 Bytes [ 73, 46, 39, 45, FC, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + 88 774D2CF3 27 Bytes [ CA, 83, E1, 03, F3, A4, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + A4 774D2D0F 55 Bytes [ FF, 22, 00, 22, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibraries + DD 774D2D48 3 Bytes [ 8B, FF, 55 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 3B 774D2E57 165 Bytes [ 45, 10, A5, 8B, F0, 8D, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 106 774D2F22 3 Bytes [ 55, 8B, EC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 10A 774D2F26 42 Bytes [ C1, 8B, 4D, 08, 56, 8B, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 135 774D2F51 34 Bytes [ 4D, 20, 89, 48, 24, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeUnusedLibrariesEx + 158 774D2F74 26 Bytes [ FF, 55, 8B, EC, 51, F6, 05, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 15 774D3B72 23 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 2D 774D3B8A 1 Byte [ 83 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 2F 774D3B8C 23 Bytes [ 1D, 74, 34, 2D, E6, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 47 774D3BA4 37 Bytes [ 2D, F9, 00, 00, 00, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterface + 6D 774D3BCA 75 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 118 774D45D5 6 Bytes [ 8B, CF, E8, 1D, A2, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 11F 774D45DC 5 Bytes [ 50, E8, 7F, A2, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 125 774D45E2 4 Bytes [ 85, C0, 0F, 85 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 12A 774D45E7 133 Bytes [ 16, 06, 00, 8D, 46, 04, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReleaseStgMedium + 1B0 774D466D 37 Bytes [ 85, FF, 7C, 30, 8B, 46, 24, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + 3A 774D4ACE 125 Bytes [ FF, 85, C0, 7C, 07, 81, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + B8 774D4B4C 11 Bytes [ 8B, 03, 8B, 4D, 18, 89, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + C4 774D4B58 13 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + D2 774D4B66 5 Bytes [ 75, 1C, FF, 75, 18 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObjectContext + D8 774D4B6C 2 Bytes [ 75, 14 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateFreeThreadedMarshaler + 3B 774D5575 111 Bytes [ 75, 0C, 33, F6, 46, 89, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateFreeThreadedMarshaler + AB 774D55E5 100 Bytes [ 15, 5C, 10, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCallContext + 49 774D564A 143 Bytes [ 00, 89, 06, 33, C0, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + 58 774D56DA 10 Bytes [ 05, AC, 6E, 5D, 77, 8B, CE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + 63 774D56E5 99 Bytes [ FF, 5F, 5E, 5D, C2, 04, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + C7 774D5749 4 Bytes [ EC, 81, EC, 4C ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + CD 774D574F 9 Bytes [ 00, 53, 8B, D9, 56, 8D, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassObject + D8 774D575A 17 Bytes [ 8B, 08, 57, 89, 4D, F4, 03, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + 10 774D6A2F 183 Bytes [ 89, 45, AC, 8B, 06, 33, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + C8 774D6AE7 31 Bytes [ 5D, C4, 7C, 40, FF, 75, AC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + E8 774D6B07 5 Bytes [ 45, C0, 8B, 08, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + EE 774D6B0D 36 Bytes [ 51, 08, 39, 7D, C4, 8B, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterChannelHook + 116 774D6B35 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 2F 774D6D1C 100 Bytes [ 00, 00, 8B, 5E, 38, 89, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 94 774D6D81 8 Bytes [ 85, C0, 89, 45, E8, 0F, 8C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + 9D 774D6D8A 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + A8 774D6D95 57 Bytes CALL EECA2E1F
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeSecurity + E3 774D6DD0 155 Bytes [ 89, 45, E0, B9, A0, 61, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 7D 774D806D 15 Bytes [ 0F, 85, D4, 02, 00, 00, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 8D 774D807D 26 Bytes [ 8D, BD, B4, FB, FF, FF, AB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + A9 774D8099 47 Bytes [ 89, 9D, D0, FB, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + DA 774D80CA 55 Bytes [ 0F, 85, BF, D1, 00, 00, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterClassObject + 112 774D8102 35 Bytes [ 93, 5D, 77, FF, 15, 04, 16, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 2 774DA340 34 Bytes [ FF, 0F, 8C, 84, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 25 774DA363 5 Bytes [ B5, E0, FD, FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 2B 774DA369 20 Bytes [ D6, 85, C0, 0F, 85, 81, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 40 774DA37E 69 Bytes [ FF, 50, 8D, 85, D4, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryClientBlanket + 86 774DA3C4 41 Bytes [ 15, 40, 10, 4B, 77, 5F, 5E, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetProxyBlanket + 12 774DAD35 3 Bytes [ EC, FF, 75 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 45 774DAD99 31 Bytes [ C8, 8D, 45, D4, 6A, 01, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 67 774DADBB 43 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IIDFromString + 93 774DADE7 62 Bytes [ 00, FF, 75, 10, 8B, 40, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 3A 774DAE26 199 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 102 774DAEEE 1 Byte [ 4D ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 104 774DAEF0 7 Bytes [ 56, FF, 75, 0C, E8, 2D, A3 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 10D 774DAEF9 34 Bytes [ 85, C0, 0F, 85, A9, 1D, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetPSClsid + 130 774DAF1C 11 Bytes [ 00, A1, 04, 60, 5D, 77, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 17 774DF9CE 1 Byte [ E8 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 1A 774DF9D1 2 Bytes [ 70, D0 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 21 774DF9D8 29 Bytes [ 3B, C3, 0F, 8C, E5, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 40 774DF9F7 254 Bytes [ 06, 8D, 4D, EC, 51, 68, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCopyProxy + 13F 774DFAF6 4 Bytes [ 3D, 02, 40, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSwitchCallContext + 24 774DFC1B 20 Bytes [ 85, 64, FF, FF, FF, 8B, 78, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 1 774DFC30 4 Bytes [ 06, 8D, 4D, 80 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 7 774DFC36 58 Bytes [ 8D, 6C, FF, FF, FF, 51, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 42 774DFC71 2 Bytes [ 45, 80 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 45 774DFC74 15 Bytes [ 75, 8C, 8D, 8D, 74, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevertToSelf + 55 774DFC84 43 Bytes [ FF, F7, DF, 1B, FF, 6A, 04, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + A 774E06A0 75 Bytes [ 85, DB, 0F, 85, 43, 77, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 56 774E06EC 57 Bytes [ FF, 75, 10, 8B, 45, 08, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 90 774E0726 4 Bytes [ F9, 89, 45, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + 95 774E072B 54 Bytes [ 47, 04, F7, D0, A8, 01, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FreePropVariantArray + CC 774E0762 6 Bytes [ F8, 85, FF, 0F, 8C, F9 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 11 774E14B5 241 Bytes [ 08, 50, FF, 51, 08, 89, 3D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 103 774E15A7 24 Bytes [ 75, 10, 8B, 5D, 0C, E9, 0B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 11C 774E15C0 4 Bytes [ 8F, 24, CF, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 160 774E1604 29 Bytes [ 8B, 3D, A4, 10, 4B, 77, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptorFromTypeInfo + 17E 774E1622 3 Bytes [ 1D, 24, 12 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + 24 774E3BC0 92 Bytes [ 85, C0, 74, 1E, 89, 73, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + 81 774E3C1D 64 Bytes [ 90, 90, 90, FF, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgID + C2 774E3C5E 23 Bytes [ 5E, C9, C2, 08, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 13 774E3C76 19 Bytes [ 0F, 85, B3, 2A, 04, 00, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 27 774E3C8A 46 Bytes [ 75, 0C, 8B, CF, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 56 774E3CB9 8 Bytes [ 80, 05, 00, 5F, 5E, 5D, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 5F 774E3CC2 6 Bytes [ 90, 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromOle1Class + 66 774E3CC9 17 Bytes [ 55, 8B, EC, 8D, 45, 0C, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 31 774E4032 59 Bytes [ 51, 04, 83, C6, 54, 56, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 6D 774E406E 35 Bytes [ 55, 8B, EC, 56, 8B, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 91 774E4092 53 Bytes [ 55, 8B, EC, 8B, 45, 0C, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + C7 774E40C8 210 Bytes [ F0, 33, DB, F3, A7, 0F, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MkParseDisplayName + 19A 774E419B 9 Bytes [ 4C, 77, C7, 46, 18, 74, 22, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 22 774E4752 76 Bytes [ 07, 50, FF, 15, 28, 15, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 6F 774E479F 32 Bytes [ FF, 89, 73, 74, 0F, B6, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + 90 774E47C0 37 Bytes [ FF, 89, 46, 28, 8D, 46, 38, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + B6 774E47E6 7 Bytes [ FF, 50, 8D, 4D, FC, E8, 0A ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetObject + BE 774E47EE 5 Bytes [ 00, 00, E9, 46, D8 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 10 774E6E47 76 Bytes [ 01, 00, 8B, 4E, 40, 56, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 5D 774E6E94 64 Bytes [ 6A, 04, 8D, 45, CC, 50, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 9E 774E6ED5 145 Bytes [ 85, B1, E1, 04, 00, 57, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 130 774E6F67 31 Bytes [ 76, 38, 8D, 46, 28, FF, 76, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSuspendClassObjects + 150 774E6F87 36 Bytes [ 08, FF, FF, 00, 80, E9, C7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 6F 774E7633 3 Bytes [ 11, A2, 05 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 73 774E7637 39 Bytes [ 8B, 45, 0C, 89, 08, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 9B 774E765F 113 Bytes [ 8B, 75, 0C, 57, 6A, 04, 59, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 10D 774E76D1 39 Bytes [ B8, 02, 40, 00, 80, 5F, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryProxyBlanket + 135 774E76F9 63 Bytes [ 00, F7, D8, 1B, C0, F7, D8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 25 774E849F 146 Bytes [ 00, 00, 85, C0, 0F, 8C, 29, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + B8 774E8532 33 Bytes CALL 004E8538
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 136 774E85B0 9 Bytes [ B9, 68, 60, 5D, 77, E8, F5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 14F 774E85C9 12 Bytes [ 56, 8B, 75, 08, 85, F6, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantClear + 15C 774E85D6 10 Bytes [ 06, 8D, 4D, 08, 51, 68, 3C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetErrorInfo + 5D 774E947C 68 Bytes [ 55, 8B, EC, 51, 53, 57, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetErrorInfo + A2 774E94C1 317 Bytes [ 83, F8, 15, 0F, 8F, A3, 5C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + 9D 774E95FF 11 Bytes [ 56, 04, 00, 8D, 85, F8, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + A9 774E960B 2 Bytes [ 73, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + AE 774E9610 26 Bytes [ F8, 85, FF, 0F, 8C, 08, 94, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + C9 774E962B 23 Bytes [ FF, 50, 68, CC, EE, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeClassObject + E1 774E9643 42 Bytes [ B5, F8, FD, FF, FF, FF, 15, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 6 774EA5B5 5 Bytes [ 56, 57, 33, FF, BE ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + C 774EA5BB 45 Bytes [ 60, 5D, 77, 8B, CE, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + D8 774EA687 58 Bytes [ 01, 04, 80, EB, F4, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 113 774EA6C2 55 Bytes [ 45, E4, 50, FF, 35, D8, 6D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetComCatalog + 14B 774EA6FA 17 Bytes [ C9, C2, 08, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 4 774EE4B0 65 Bytes [ C7, 5F, 5E, 5D, C2, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 46 774EE4F2 2 Bytes [ 55, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 49 774EE4F5 48 Bytes [ 53, 8B, 5D, 0C, 85, DB, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + 7A 774EE526 130 Bytes [ C0, 7C, 0A, 8B, 45, 0C, 0D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetTreatAsClass + FD 774EE5A9 12 Bytes [ 8B, 45, 0C, 8B, 08, 56, 68, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 14 774EFA56 36 Bytes [ 57, FF, 75, 18, FF, 75, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 39 774EFA7B 75 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 85 774EFAC7 17 Bytes CALL CA4EFAC9
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + 97 774EFAD9 10 Bytes [ F0, 85, F6, 0F, 8C, A1, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisconnectObject + A3 774EFAE5 212 Bytes [ 08, 57, BF, 6C, CA, 4B, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 2F 774EFD69 107 Bytes [ 00, 75, 30, FF, 75, 08, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 9B 774EFDD5 28 Bytes [ 75, FC, FF, 15, 40, 10, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + B8 774EFDF2 12 Bytes [ 83, FB, 01, 0F, 82, 9F, D4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + C5 774EFDFF 82 Bytes [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromString + 118 774EFE52 14 Bytes [ C3, 5B, 5D, C2, 0C, 00, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 54 774F09F3 13 Bytes [ 74, 1D, 56, 33, F6, 39, 35, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 62 774F0A01 17 Bytes [ 4C, F0, 04, 85, C9, 75, 25, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + 74 774F0A13 26 Bytes [ 6A, 00, FF, 35, 00, 60, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + D0 774F0A6F 3 Bytes [ 33, E1, FD ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFreeAllLibraries + D4 774F0A73 204 Bytes [ 85, C0, 0F, 84, 63, D5, 03, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + AB 774F391F 23 Bytes [ 4D, 0C, 89, 08, 57, 8B, CE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + C3 774F3937 46 Bytes CALL 775117D3 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + F2 774F3966 9 Bytes [ 3B, 46, 48, 0F, 82, 0C, DF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + FC 774F3970 54 Bytes [ 7E, 40, FF, 74, 1D, 6A, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetRunningObjectTable + 134 774F39A8 3 Bytes [ 90, 90, 90 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 2 774F3EE9 114 Bytes [ 15, 2C, 14, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 75 774F3F5C 27 Bytes [ 45, FC, 5B, 5E, C9, C2, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 91 774F3F78 299 Bytes [ 02, 75, 0A, F6, 41, 08, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 1BD 774F40A4 19 Bytes [ 88, 5D, ED, 88, 5D, EE, 88, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllGetClassObject + 202 774F40E9 8 Bytes CALL CAA2943E
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 37 774F46AF 75 Bytes [ 60, 5D, 77, FF, 15, 54, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 85 774F46FD 114 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + F8 774F4770 72 Bytes [ 5F, 5E, 5D, C2, 04, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 144 774F47BC 45 Bytes [ 8B, FF, 55, 8B, EC, F6, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromCLSID + 172 774F47EA 13 Bytes [ 45, 08, 83, 08, FF, EB, E1, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + A3 774F5BA6 26 Bytes [ 00, 10, 0F, 85, AC, 0E, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + BE 774F5BC1 4 Bytes [ 84, 28, 23, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + F5 774F5BF8 12 Bytes [ 75, 1D, A8, 08, 74, 19, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + 102 774F5C05 55 Bytes [ 66, 64, 00, 83, 66, 60, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReleaseMarshalData + 13A 774F5C3D 37 Bytes [ 83, 7D, FC, 00, 74, 0A, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + B8 774F681F 96 Bytes [ 4E, 64, 8B, 49, 20, 3B, C8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 119 774F6880 26 Bytes [ FF, 51, 0C, 85, C0, 7C, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 134 774F689B 1 Byte [ F6 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 136 774F689D 1 Byte [ 8C ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DcomChannelSetHResult + 13B 774F68A2 58 Bytes [ 83, 7F, 04, 08, 0F, 85, 99, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax 774F7DC7 33 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 22 774F7DE9 3 Bytes [ BF, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 29 774F7DF0 7 Bytes [ 59, 53, 8D, 86, B4, 01, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 31 774F7DF8 82 Bytes [ 50, BB, 57, 00, 07, 80, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetMarshalSizeMax + 85 774F7E4C 1 Byte [ 5D ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface 774F7EFB 6 Bytes [ 90, 90, 8B, FF, 55, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + 7 774F7F02 183 Bytes [ 83, EC, 34, 53, 8B, D9, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + BF 774F7FBA 32 Bytes [ 45, FC, 2B, F0, 39, 55, E0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + E0 774F7FDB 18 Bytes [ 15, 54, 61, 5D, 77, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalInterface + F4 774F7FEF 1 Byte [ D4 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 24 774F9AFB 229 Bytes [ 7C, 61, F6, 45, 0D, 40, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 10C 774F9BE3 41 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 136 774F9C0D 77 Bytes [ 47, 04, 5F, 5E, 5D, C2, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 184 774F9C5B 8 Bytes [ 45, FC, 89, 43, 04, 8B, 48, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoImpersonateClient + 18D 774F9C64 15 Bytes [ 0B, FF, 40, 10, 89, 58, 14, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 45 774FA061 10 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 50 774FA06C 27 Bytes [ 4D, 08, 6A, 01, FF, 75, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 6C 774FA088 39 Bytes [ FF, 55, 8B, EC, 83, EC, 2C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + 94 774FA0B0 44 Bytes [ FF, FF, 3B, C6, 89, 45, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoadFromStream + C1 774FA0DD 3 Bytes [ 25, F0, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 5A 774FA14B 2 Bytes [ 0F, B7 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 5D 774FA14E 23 Bytes [ 0C, 83, 24, 87, 00, FF, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 75 774FA166 68 Bytes [ FF, FF, B9, F8, 6D, 5D, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + BB 774FA1AC 16 Bytes [ B5, CF, FF, FF, 8B, 08, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStm + 11C 774FA20D 1 Byte [ 25 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 13 774FA2E3 39 Bytes [ 00, 00, 3B, C7, 0F, 84, 16, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 3B 774FA30B 38 Bytes [ 90, 90, 90, 90, 90, 8B, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 62 774FA332 66 Bytes [ 01, 80, 0F, 84, F4, DE, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + A6 774FA376 100 Bytes [ 8D, B0, 80, 00, 00, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateGenericComposite + 10B 774FA3DB 187 Bytes [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 80 774FB51E 77 Bytes [ 00, 8B, 7D, 14, 3B, FB, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + CE 774FB56C 28 Bytes [ C0, 0F, 85, 42, 45, 03, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + EB 774FB589 54 Bytes [ 85, C0, 0F, 85, 5D, 45, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 122 774FB5C0 80 Bytes [ FF, FF, 75, 10, 8B, B5, 3C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStreamOnHGlobal + 173 774FB611 156 Bytes [ 5D, 18, F6, C7, 20, 56, 57, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 25 774FC9F0 20 Bytes [ 00, 8D, 45, C4, 50, 6A, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 3A 774FCA05 203 Bytes [ 15, 58, 10, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 106 774FCAD1 29 Bytes [ FF, 3B, C6, 89, 45, F8, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 124 774FCAEF 70 Bytes [ FF, 15, E4, 12, 4B, 77, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorage + 16B 774FCB36 1 Byte [ 4F ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 1F 775029CD 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 23 775029D1 5 Bytes [ FF, 55, 8B, EC, 51 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTaskMemRealloc + 29 775029D7 88 Bytes [ 56, 57, 8B, 3D, 8C, 14, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 31 77502A30 4 Bytes [ 85, 23, 8B, 03 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 36 77502A35 13 Bytes [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 44 77502A43 5 Bytes [ 50, 04, 85, C0, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + 4A 77502A49 149 Bytes [ C4, 54, FE, FF, C7, 46, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!RevokeDragDrop + E0 77502ADF 2 Bytes [ 47, 10 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 2D 77502C71 38 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 54 77502C98 2 Bytes [ 46, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 57 77502C9B 31 Bytes [ 0E, 89, 08, 89, 41, 04, 5F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + 77 77502CBB 41 Bytes [ FF, 55, 8B, EC, 83, EC, 1C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeNow + A1 77502CE5 4 Bytes CALL 775033AA C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserFree + E 77502EA6 13 Bytes [ FF, 5E, C9, C3, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserFree + 1F 77502EB7 145 Bytes [ 8B, C0, C3, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 3F 77502F4A 66 Bytes [ 0D, D4, 62, 5D, 77, 85, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 82 77502F8D 8 Bytes [ FC, FF, 8B, C6, 5E, 5D, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 8B 77502F96 70 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + D2 77502FDD 89 Bytes [ 3D, 30, 12, 4B, 77, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetClipboard + 12C 77503037 102 Bytes [ 33, C0, 5F, 5E, 5B, C9, C3, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize 77503343 50 Bytes [ 90, 8B, FF, 55, 8B, EC, A1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + 33 77503376 103 Bytes [ 8D, 4D, E4, C7, 45, E4, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + 9E 775033E1 22 Bytes [ 90, 8B, FF, 55, 8B, EC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + B5 775033F8 16 Bytes [ 8B, 49, 08, 83, C2, 10, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleUninitialize + C6 77503409 18 Bytes [ 5D, C2, 04, 00, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryLinkFromData + 11 77503503 3 Bytes [ 2C, 30, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryLinkFromData + 15 77503507 44 Bytes [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 10 77503534 40 Bytes [ 00, 00, 8B, 00, 03, 46, 40, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 39 7750355D 8 Bytes [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + 42 77503566 110 Bytes [ 00, 03, 46, 40, 89, 08, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + B1 775035D5 56 Bytes [ 75, 18, FF, 75, 14, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleQueryCreateFromData + EA 7750360E 33 Bytes [ F9, 8B, 57, 74, 33, C0, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 12 77503D05 58 Bytes [ 39, 41, 6C, 74, 11, 64, A1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 4D 77503D40 9 Bytes [ F8, 0F, 8D, 4B, FC, FE, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 57 77503D4A 5 Bytes [ FE, FF, 33, C0, E9 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 5D 77503D50 33 Bytes [ 2C, 01, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLockObjectExternal + 7F 77503D72 52 Bytes [ 8B, 45, 08, 57, 0F, 84, 91, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B 77503FB3 26 Bytes [ 00, 00, 8B, 80, B0, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + 26 77503FCE 137 Bytes [ 01, 5F, C9, C2, 04, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B0 77504058 3 Bytes [ 85, 23, 06 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + B5 7750405D 38 Bytes [ 5D, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateFileMoniker + DC 77504084 12 Bytes [ D6, 85, C0, 75, 4E, 0F, B7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 1B 7750467A 13 Bytes [ 8B, EC, 83, 39, 00, 56, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 2A 77504689 76 Bytes [ 80, 80, 0F, 00, 00, 8B, 30, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 78 775046D7 7 Bytes [ FF, 3D, 57, 44, 46, 4C, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + 80 775046DF 40 Bytes [ 79, E5, 03, 00, 5D, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentProcess + A9 77504708 13 Bytes [ 00, 8B, 80, 80, 0F, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 2D 77504811 13 Bytes CALL 77503C1B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 3B 7750481F 47 Bytes [ C1, EE, 10, 56, 8B, CF, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 6B 7750484F 256 Bytes [ 00, 89, 45, FC, 5F, 5E, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 16C 77504950 55 Bytes [ FF, 0F, 8D, 28, 14, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStandardMarshal + 1A5 77504989 9 Bytes [ BE, 57, 00, 07, 80, E9, C5, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 2 77505491 16 Bytes [ FF, BB, 57, 00, 07, 80, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 44 775054D3 6 Bytes [ FF, 50, E8, 4C, FD, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + 4B 775054DA 109 Bytes [ 85, C0, 0F, 85, 95, B1, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + E4 77505573 8 Bytes CALL 775296C1 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgSetTimes + ED 7750557C 68 Bytes [ F0, 85, F6, 0F, 85, 3C, 22, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 1D 7750AF8C 147 Bytes [ 05, 00, 8D, 50, 02, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + B1 7750B020 153 Bytes [ 5D, FC, 0F, B6, 06, 33, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 14B 7750B0BA 77 Bytes [ 24, F8, E5, 4B, 77, 53, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 199 7750B108 94 Bytes [ 3B, DF, 0F, 84, 82, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageEx + 1F8 7750B167 124 Bytes [ EC, 83, EC, 0C, 8B, 4D, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + C7 7750E198 32 Bytes [ 8D, 46, 24, 50, FF, 15, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + E8 7750E1B9 37 Bytes [ FF, FF, FF, 34, E0, 53, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 10E 7750E1DF 27 Bytes [ 00, 00, 89, 41, 0C, 89, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 12B 7750E1FC 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnHandle + 12F 7750E200 86 Bytes [ FF, 55, 8B, EC, 56, 8B, F1, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + F 7750F4F5 9 Bytes [ EC, 51, 51, 83, 65, F8, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 19 7750F4FF 26 Bytes [ 00, 66, F7, 45, 0E, 07, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 34 7750F51A 53 Bytes [ 00, 56, 68, D8, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSaveToStream + 6A 7750F550 23 Bytes [ 00, 00, 8B, F8, 85, FF, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + F 7750F568 11 Bytes [ 7C, 0C, 8B, 45, FC, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 1B 7750F574 20 Bytes [ 89, 01, 5E, 8D, 45, F8, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 30 7750F589 74 Bytes [ 81, FF, 20, 00, 03, 80, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + 7B 7750F5D4 96 Bytes [ 03, 00, F6, 45, 10, 02, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStm + DC 7750F635 18 Bytes [ FF, FF, 8B, F0, 3B, F3, 7C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 17 77514CD2 3 Bytes [ C8, D2, FD ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 1B 77514CD6 37 Bytes [ 8B, F8, 85, FF, 0F, 8C, 1E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 41 77514CFC 15 Bytes [ 74, 40, 83, 7D, E4, FF, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 74 77514D2F 4 Bytes [ 33, C0, 8A, 45 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfile + 79 77514D34 57 Bytes [ F7, D0, A8, 01, 0F, 85, 34, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStg + 2 77515F45 24 Bytes [ B5, FF, FF, 39, 5E, 14, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteClassStg + 1B 77515F5E 33 Bytes [ 00, 03, 46, 14, 3B, C3, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 13 77515F80 10 Bytes [ 00, 03, 46, 18, 3B, C3, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 1E 77515F8B 69 Bytes [ FF, 33, D2, 39, 5E, 08, 76, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 64 77515FD1 5 Bytes [ 8B, 00, 03, 46, 18 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 6A 77515FD7 33 Bytes [ 04, 90, 42, 89, 01, 3B, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadClassStg + 8C 77515FF9 71 Bytes [ 8B, 08, 03, 4E, 10, E8, 91, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 1 77517183 94 Bytes [ 75, 0C, 57, 83, EC, 10, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 60 775171E2 94 Bytes [ 8B, FC, 8D, 75, EC, A5, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + BF 77517241 48 Bytes [ EC, 81, EC, 20, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + F0 77517272 18 Bytes [ 85, C0, 0F, 84, 1D, 42, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateStorageEx + 103 77517285 57 Bytes CALL 775172C0 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 2 77517680 46 Bytes [ 7F, 0F, 83, EC, 73, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 31 775176AF 65 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 73 775176F1 60 Bytes [ 15, AC, 14, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + B0 7751772E 88 Bytes [ FF, 55, 8B, EC, 51, 53, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteFmtUserTypeStg + 109 77517787 78 Bytes [ F8, 85, FF, 0F, 84, 1E, 72, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 4 77517922 46 Bytes [ 75, 08, 6A, 00, 57, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 33 77517951 103 Bytes [ FF, 53, 56, 8B, F1, 57, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + 9B 775179B9 4 Bytes [ C6, 5E, 5B, C3 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + A0 775179BE 24 Bytes [ 7D, 0C, 00, 0F, 85, 73, 3C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteStringStream + B9 775179D7 183 Bytes CALL 775179E8 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 34 775196D6 152 Bytes [ 55, 8B, EC, 83, EC, 0C, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 136 775197D8 24 Bytes JMP 7751989A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 14F 775197F1 93 Bytes [ 56, 20, 8B, 4D, 10, 8B, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 1AD 7751984F 64 Bytes [ 8B, F8, 85, FF, 0F, 8C, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsRunning + 1EE 77519890 21 Bytes [ 10, 8B, CE, FF, 75, 0C, 53, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 29 7751A015 6 Bytes [ 8B, 76, 20, 8B, 06, 56 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 30 7751A01C 89 Bytes [ 50, 04, 8B, C6, 5E, C3, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 8A 7751A076 82 Bytes [ 07, 80, EB, F3, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + FC 7751A0E8 53 Bytes [ 3F, 8D, 4C, 09, 02, 8B, C1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerRelativePathTo + 132 7751A11E 30 Bytes [ C8, 83, E1, 03, F3, A4, 33, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus 7751A3F9 41 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 2A 7751A423 84 Bytes [ 00, 00, 89, 06, F7, D8, 1B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 7F 7751A478 125 Bytes [ 50, 04, 8B, C6, 5E, 5D, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + FD 7751A4F6 49 Bytes [ 33, C0, 5F, 5E, 5D, C2, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetMiscStatus + 12F 7751A528 34 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 36 7751A78D 11 Bytes [ CE, 0F, 85, 7A, 53, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 42 7751A799 6 Bytes [ 8B, F8, 3B, FB, 0F, 8C ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 49 7751A7A0 16 Bytes [ 53, 01, 00, 83, 4E, 44, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + 5A 7751A7B1 111 Bytes [ 8B, C7, 5F, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserMarshal + CA 7751A821 51 Bytes [ 50, FF, 51, 60, 5D, C2, 0C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 2 7751B1FA 19 Bytes [ 51, 08, 5F, 8B, C6, 5B, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 16 7751B20E 1 Byte [ FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 18 7751B210 58 Bytes [ EB, BE, FF, FF, 00, 80, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 53 7751B24B 17 Bytes CALL 7751B21C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetAutoConvert + 65 7751B25D 60 Bytes [ 8D, 4F, 5C, 89, 4D, 0C, E9, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 12 7751B627 70 Bytes [ 15, D4, 18, 4B, 77, 83, C4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 59 7751B66E 47 Bytes [ 75, 08, 8D, 75, FC, E8, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataAdviseHolder + 89 7751B69E 36 Bytes [ 04, 85, C0, 0F, 84, 78, 9E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 52 7751B6FE 22 Bytes [ 80, 3F, 03, 0F, 84, A6, 1B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 69 7751B715 14 Bytes [ EC, 8B, 45, 10, 85, C0, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 78 7751B724 138 Bytes [ 8B, 75, 0C, 83, C6, 03, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 103 7751B7AF 32 Bytes [ 37, FF, 15, 18, 11, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromFile + 124 7751B7D0 1 Byte [ 55 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 2 7751B95F 15 Bytes [ 39, 7E, 70, 0F, 85, DF, 19, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 12 7751B96F 37 Bytes [ FF, 8B, C3, 5F, 5E, 5B, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromData + 38 7751B995 7 Bytes [ 85, C0, 0F, 84, D5, 57, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 3B 7751B9E3 50 Bytes [ EC, 51, 51, 83, 65, FC, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 6E 7751BA16 37 Bytes [ 8B, 75, 0C, 85, F6, 74, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 94 7751BA3C 113 Bytes [ 85, F6, 89, 73, 48, 74, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 106 7751BAAE 132 Bytes [ 55, 8B, EC, 51, 53, 8B, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkFromDataEx + 18B 7751BB33 31 Bytes [ 08, 50, FF, 51, 20, 8B, F8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 2 7751C85E 45 Bytes [ 75, 0C, FF, 75, 08, E8, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 30 7751C88C 27 Bytes [ 00, 53, 56, 8B, 75, 0C, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 4C 7751C8A8 21 Bytes [ 51, 68, 00, 08, 00, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 62 7751C8BE 55 Bytes [ FF, 7C, 13, FF, 75, 10, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsHandlerConnected + 9A 7751C8F6 42 Bytes [ FF, 55, 8B, EC, 8B, 45, 14, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 26 7751CA30 33 Bytes [ 23, 00, 00, 8B, F8, 85, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 48 7751CA52 75 Bytes [ 21, 7D, E0, 8D, 45, CC, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + 94 7751CA9E 54 Bytes [ 45, E4, 56, FF, 75, D0, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + CB 7751CAD5 9 Bytes [ 83, 7D, E0, 00, 0F, 85, 16, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateOleAdviseHolder + D5 7751CADF 95 Bytes [ 83, 7D, CC, 00, 0F, 85, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + C7 7751DE16 62 Bytes [ C0, 8B, 35, 40, 10, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 10F 7751DE5E 14 Bytes [ 83, EC, 20, 66, A1, 60, 62, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 11E 7751DE6D 16 Bytes [ F6, 89, 75, E4, C7, 45, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 12F 7751DE7E 53 Bytes [ F0, 04, 00, 00, 00, E8, 16, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadFmtUserTypeStg + 165 7751DEB4 87 Bytes [ 45, F8, 57, 8B, 38, 56, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + A8 7751F3B6 52 Bytes [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + DD 7751F3EB 6 Bytes CALL 77503774 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + E4 7751F3F2 22 Bytes [ F8, 3B, FB, 0F, 8C, F0, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + FC 7751F40A 4 Bytes [ 8B, 80, 80, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSave + 101 7751F40F 59 Bytes [ 00, 8B, 00, 03, 46, 70, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 10 775209CF 13 Bytes [ 8B, 08, 50, FF, 51, 08, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 1E 775209DD 12 Bytes [ B5, E4, FE, FF, FF, 8D, 46, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 2B 775209EA 12 Bytes [ 1B, C0, 57, 23, C1, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 38 775209F7 3 Bytes [ 71, FC, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetHGlobalFromILockBytes + 3C 775209FB 59 Bytes [ 8B, F8, 33, C0, 3B, F8, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + A 77520DDD 55 Bytes [ 00, 39, 7D, 08, 89, 7E, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 42 77520E15 1 Byte [ 55 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 44 77520E17 66 Bytes [ EC, 56, 8B, 75, 08, 8D, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 87 77520E5A 2 Bytes [ CF, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateILockBytesOnHGlobal + 8B 77520E5E 31 Bytes [ C3, 90, 90, 90, 90, 90, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + 82 77520F85 48 Bytes [ 33, F6, 8B, 4D, 08, E8, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + B3 77520FB6 8 Bytes [ 55, 8B, EC, 56, 8B, F1, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + BD 77520FC0 26 Bytes [ 00, F6, 45, 08, 01, 74, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + D8 77520FDB 10 Bytes [ 04, 00, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreateDocfileOnILockBytes + E3 77520FE6 72 Bytes [ F1, 8B, 46, 14, 57, 33, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + E 7752207F 25 Bytes [ 5F, 8B, C6, 5E, C9, C2, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 28 77522099 23 Bytes [ F7, EF, FC, FF, 8B, C8, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 40 775220B1 39 Bytes [ 15, 50, 61, 5D, 77, E9, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + 68 775220D9 66 Bytes [ FF, 36, 50, FF, 75, 08, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateErrorInfo + AB 7752211C 69 Bytes [ 46, 3D, FF, 7F, 00, 00, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 2C 77522ABA 18 Bytes [ 00, FF, B5, 58, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 60 77522AEE 1 Byte [ 56 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 62 77522AF0 10 Bytes [ 35, 50, 10, 4B, 77, 57, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserSize + 6D 77522AFB 17 Bytes [ 75, 08, 33, FF, 68, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserMarshal + A 77522B0E 72 Bytes [ BF, F3, 01, 04, 80, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserMarshal + 53 77522B57 40 Bytes [ 84, 80, 20, FC, FF, E9, F4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + B 77522B80 6 Bytes [ 85, C0, 59, 74, 39, 57 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 12 77522B87 47 Bytes CALL 77522BC6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 54 77522BC9 30 Bytes [ 55, 8B, EC, 53, 56, 57, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserMarshal + 73 77522BE8 85 Bytes [ BE, 3C, 1A, 4B, 77, A5, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserSize + 50 77522C3E 101 Bytes [ 00, 00, EB, 56, C7, 46, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserFree + 48 77522CA4 50 Bytes [ 15, 24, 12, 4B, 77, 83, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserFree + 7B 77522CD7 149 Bytes [ 80, 80, 0F, 00, 00, 8B, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserUnmarshal + 71 77522D6D 133 Bytes CALL 77522D7B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!STGMEDIUM_UserUnmarshal + F7 77522DF3 59 Bytes [ 5E, C3, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + 2 77522E2F 106 Bytes [ 15, 54, 61, 5D, 77, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + 6D 77522E9A 84 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + C2 77522EEF 15 Bytes [ 83, 4D, FC, FF, 8B, 45, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + D2 77522EFF 1 Byte [ 90 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLIPFORMAT_UserUnmarshal + D4 77522F01 12 Bytes [ FF, FF, FF, CC, 1B, 53, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 7 77523191 11 Bytes [ D8, 85, DB, 0F, 8C, 41, CE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 13 7752319D 59 Bytes [ 0A, 8B, 4D, F8, 8B, 3C, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 4F 775231D9 30 Bytes [ 02, 0F, B7, 49, 1C, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 6E 775231F8 1 Byte [ 98 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserMarshal + 70 775231FA 114 Bytes CALL 77523209 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + 4A 7752326D 93 Bytes [ 7D, A0, C7, 04, 87, FC, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + A8 775232CB 34 Bytes [ FF, 55, 8B, EC, 51, 51, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + CC 775232EF 34 Bytes [ 03, 46, 18, 39, 58, 1C, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + EF 77523312 10 Bytes [ 03, 46, 18, 39, 5E, 18, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserSize + FA 7752331D 80 Bytes [ 64, A1, 18, 00, 00, 00, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 7E 7752399E 168 Bytes [ 83, F8, 2C, 74, 7E, 66, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 128 77523A48 2 Bytes [ 48, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 12B 77523A4B 22 Bytes [ 6B, F2, 00, 00, 8D, 46, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 143 77523A63 32 Bytes [ 6A, 00, FF, 35, 00, 60, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetClipboard + 164 77523A84 53 Bytes JMP 775051B7 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoIsOle1Class + 22 77524886 13 Bytes [ 69, 00, 6E, 00, 73, 00, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 9 77524894 120 Bytes [ 6C, 00, 6C, 00, 00, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 82 7752490D 190 Bytes JMP 77503DA5 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 141 775249CC 7 Bytes [ 56, FF, 75, 08, 89, 45, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 149 775249D4 159 Bytes [ 15, 18, 18, 4B, 77, E9, 16, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StringFromIID + 1E9 77524A74 16 Bytes [ 85, F6, 7C, 1A, 8D, 85, 7C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + 8F 77524BD1 15 Bytes [ 0F, B7, 70, 02, 8D, 74, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + 9F 77524BE1 39 Bytes [ CB, 8B, 1A, 8D, 7C, 7B, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + C7 77524C09 2 Bytes [ 45, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + CA 77524C0C 4 Bytes [ 4D, 10, 89, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ProgIDFromCLSID + CF 77524C11 48 Bytes [ 08, 50, FF, 51, 04, 33, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 22 77525276 24 Bytes [ 85, DB, 0F, 84, C6, 6C, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 3B 7752528F 30 Bytes [ 00, 8D, 73, 04, A5, A5, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 5A 775252AE 50 Bytes [ 08, FF, 75, F8, FF, 15, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + 8D 775252E1 68 Bytes [ 0F, 85, A3, 8C, 01, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateItemMoniker + D2 77525326 54 Bytes [ 00, 56, FF, 75, 1C, 8B, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 23 77525762 37 Bytes [ FF, 15, 24, 12, 4B, 77, 3D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 83 775257C2 7 Bytes [ 0C, 89, 51, 04, 83, C1, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 8B 775257CA 63 Bytes [ C0, 10, FF, 45, F4, 89, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + CB 7752580A 130 Bytes [ 7F, 05, 02, 40, 00, 80, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMessageFilter + 14E 7752588D 33 Bytes [ 55, 8B, EC, 83, 7D, 08, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 2F 77526139 10 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 3A 77526144 18 Bytes CALL 77526161 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetMenuDescriptor + 4D 77526157 50 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRun 7752618A 14 Bytes [ 90, 90, 90, 90, 8B, FF, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRun + F 77526199 129 Bytes [ 3B, C7, 74, 15, 50, 57, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 4D 7752621B 1 Byte [ C0 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 4F 7752621D 5 Bytes [ 46, 14, 89, 46, 20 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 55 77526223 18 Bytes [ 46, 18, 89, 46, 24, 66, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 68 77526236 186 Bytes [ 46, 28, C7, 46, 30, 78, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CLSIDFromProgIDEx + 123 775262F1 167 Bytes [ 1C, 00, 00, 00, 85, C0, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 2C 77526A8B 37 Bytes [ 8B, 45, 08, 8B, 38, 8B, 58, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 53 77526AB2 50 Bytes CALL 77526AC9 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 86 77526AE5 3 Bytes [ 8D, 81, D0 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + 8A 77526AE9 34 Bytes [ 00, 00, 3B, 38, 74, 47, 42, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateClassMoniker + AD 77526B0C 53 Bytes [ 89, 41, 24, 8B, 74, C1, 28, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 2 77526D98 28 Bytes [ 50, FF, 15, BC, 10, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 1F 77526DB5 3 Bytes [ 00, 00, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 23 77526DB9 80 Bytes [ 03, 46, 1C, 83, C0, 70, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 74 77526E0A 7 Bytes JMP 7750FF7B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterfaceAndReleaseStream + 7E 77526E14 5 Bytes [ 8B, FF, 55, 8B, EC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + 19 77526E9F 38 Bytes [ 55, 8B, EC, 83, EC, 0C, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + 40 77526EC6 109 Bytes [ 77, 50, FF, 15, 24, 18, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + AE 77526F34 25 Bytes CALL 77526E2C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + C9 77526F4F 31 Bytes [ 8B, C7, 5F, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoMarshalInterThreadInterfaceInStream + EA 77526F70 26 Bytes [ C0, 89, 45, FC, 0F, 84, B5, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 16 77527127 41 Bytes [ 35, 88, 18, 4B, 77, FF, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 41 77527152 2 Bytes [ 71, 91 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 45 77527156 14 Bytes [ 8B, 45, FC, 5F, 5E, 5B, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 54 77527165 1 Byte [ 04 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoWaitForMultipleHandles + 56 77527167 29 Bytes [ EB, ED, 90, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserUnmarshal + 14 77542EF3 40 Bytes JMP 7750AC7E C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserUnmarshal + 3D 77542F1C 26 Bytes [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 13 77542F38 16 Bytes [ 74, 16, 64, A1, 18, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 24 77542F49 22 Bytes [ 8E, 8C, 00, 00, 00, EB, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + 3B 77542F60 113 Bytes [ 00, 00, 8B, 80, 80, 0F, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + AD 77542FD2 51 Bytes CALL 77513779 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserMarshal + E1 77543006 38 Bytes CALL 7751F8DD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + 13 7754302E 28 Bytes [ 4D, 08, 66, 83, B9, 82, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + 30 7754304B 92 Bytes [ 8B, F0, 83, C0, F4, F7, DE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + AB 775430C6 20 Bytes [ 66, 04, 00, 83, 26, 00, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + C2 775430DD 33 Bytes [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserSize + E4 775430FF 36 Bytes [ 8B, CB, 89, 45, E4, E8, 80, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 19 77544F16 11 Bytes [ 89, 01, FF, 15, FC, 12, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 25 77544F22 23 Bytes [ 04, 8B, CE, EB, 2B, E8, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 3D 77544F3A 6 Bytes [ 75, F8, E8, F8, 07, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + 44 77544F41 177 Bytes [ 8B, F8, 85, FF, 7C, 12, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!WriteOleStg + F6 77544FF3 8 Bytes [ 20, FF, 75, 1C, FF, 75, 18, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + 5A 77545A6C 73 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + A4 77545AB6 15 Bytes [ 8D, 46, 04, 8B, 08, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + B4 77545AC6 4 Bytes [ DF, 03, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + BB 77545ACD 15 Bytes [ 11, 8B, 46, 30, 8B, 08, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadStringStream + CB 77545ADD 139 Bytes [ 75, 24, 85, DB, 74, 20, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 1 77545C50 10 Bytes [ 7D, F4, 6A, 05, 59, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + D 77545C5C 26 Bytes [ F4, F3, A5, 8B, 08, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 28 77545C77 3 Bytes [ 74, 1D, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 2D 77545C7C 37 Bytes [ 8B, 43, 18, 8B, 08, 8D, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageFile + 53 77545CA2 51 Bytes [ 83, C3, 20, FF, 4D, EC, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 3B 77545D44 56 Bytes CALL 77523BEE C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 74 77545D7D 23 Bytes [ B8, FF, FF, FF, 7F, 80, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 8C 77545D95 9 Bytes [ C2, 0C, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + 96 77545D9F 27 Bytes [ 55, 8B, EC, 83, 7D, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegGetUserType + B3 77545DBC 3 Bytes [ B5, DD, FD ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 3B 7754720E 6 Bytes [ 76, 8B, CB, E8, A2, CC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 42 77547215 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 45 77547218 4 Bytes [ 74, 6B, 83, 7E ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 4A 7754721D 24 Bytes [ FF, 74, 10, 83, 7D, 0C, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ReadOleStg + 63 77547236 25 Bytes [ FF, 75, 0C, 50, FF, 51, 58, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + 11 7754743B 92 Bytes [ 00, 00, 89, 86, AC, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + 6E 77547498 89 Bytes CALL 77525862 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + C9 775474F3 37 Bytes [ 8B, D8, EB, 13, 3B, C6, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + EF 77547519 12 Bytes [ 8D, 73, 30, 8B, 06, 56, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDoAutoConvert + FC 77547526 56 Bytes [ 45, 10, 25, 00, 02, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + AE 77547972 38 Bytes [ F8, FF, 3B, F3, 7D, 28, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + D5 77547999 41 Bytes [ BE, 1D, 01, 01, 80, EB, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + FF 775479C3 124 Bytes [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + 17C 77547A40 71 Bytes [ 56, 8B, 75, 10, 85, F6, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoBuildVersion + 1C4 77547A88 64 Bytes CALL 7FA207DD
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 97 77547C8C 66 Bytes CALL 7759C5C2 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + DB 77547CD0 6 Bytes [ 11, 57, E8, 42, 67, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + E2 77547CD7 39 Bytes [ 85, C0, 75, 07, B8, 57, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 10A 77547CFF 42 Bytes [ C0, 74, 06, 8B, 08, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumVerbs + 135 77547D2A 98 Bytes [ 51, 50, FF, 52, 10, F6, 46, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 16 77547F4A 261 Bytes [ 50, FF, 51, 14, 85, C0, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 11C 77548050 5 Bytes [ BE, 80, 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 122 77548056 58 Bytes [ 07, 85, C0, 74, 09, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 15D 77548091 33 Bytes [ F6, 0F, 84, BB, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLoad + 17F 775480B3 94 Bytes [ 75, 0C, 83, 26, 00, E8, 5C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 3B 775484CA 11 Bytes [ DB, 74, 1D, 8D, 45, EC, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 47 775484D6 5 Bytes [ FF, FF, 75, E4, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 4D 775484DC 8 Bytes CALL 7751867C C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 56 775484E5 21 Bytes [ EC, A5, A5, A5, A5, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!IsAccelerator + 6C 775484FB 102 Bytes [ 4D, FC, 5F, 5E, 8B, C3, 5B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + 8C 775486C4 26 Bytes CALL 7759D785 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + A7 775486DF 66 Bytes [ 00, EB, 10, 6A, 01, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + EA 77548722 12 Bytes [ 10, 53, FF, 75, 80, 8D, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + F7 7754872F 115 Bytes [ 85, C0, 74, 4E, 8B, 45, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleTranslateAccelerator + 16B 775487A3 120 Bytes [ 46, 34, 8B, 08, 50, FF, 51, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 44 7754898A 72 Bytes CALL 77519C33 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 8D 775489D3 299 Bytes [ C7, 41, 1C, 80, E1, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 1B9 77548AFF 75 Bytes [ 50, FF, 51, 0C, 8B, D8, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 205 77548B4B 18 Bytes [ 85, C0, 74, 11, 6A, 04, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateMenuDescriptor + 218 77548B5E 21 Bytes [ 00, 00, 57, 8D, 7E, E4, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserFree + 6 77548B74 18 Bytes [ 08, 50, FF, 51, 14, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserFree + 19 77548B87 65 Bytes [ 44, 8B, 46, 2C, 8B, 08, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserUnmarshal + 31 77548BC9 1 Byte [ 80 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HGLOBAL_UserUnmarshal + 33 77548BCB 21 Bytes [ 0C, 53, 83, C6, 40, 56, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 1 77548BE1 66 Bytes [ C7, 5F, EB, 05, B8, 57, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 63 77548C43 49 Bytes [ 00, 68, 78, 8C, 5D, 77, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 95 77548C75 5 Bytes [ 89, 18, 8B, 03, 53 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + 9B 77548C7B 10 Bytes [ 50, 04, 8B, 03, 53, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDestroyMenuDescriptor + A6 77548C86 10 Bytes [ B5, F4, FD, FF, FF, 8B, 03, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 20 7754940A 7 Bytes [ F0, 85, F6, 7C, 48, C7, 45 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 28 77549412 66 Bytes [ 01, 00, 00, 00, 8B, CB, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 6B 77549455 27 Bytes [ 50, 18, 8B, 4D, FC, E8, D5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + 87 77549471 103 Bytes [ EC, 56, 8B, 75, 08, 57, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleInitializeWOW + EF 775494D9 180 Bytes [ 00, 39, 75, 08, 0F, 84, B1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 12 7754958F 29 Bytes [ 00, 33, F6, 5F, 5B, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 30 775495AD 19 Bytes [ 15, 50, 61, 5D, 77, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInitializeWOW + 44 775495C1 36 Bytes [ 55, 8B, EC, 53, 56, 8B, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnmarshalHresult + 1C 775495E6 85 Bytes [ D7, 66, 85, C0, 7D, 31, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 2F 7754963C 80 Bytes [ EC, 53, 56, 57, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 80 7754968D 22 Bytes [ 45, 0C, 50, 57, FF, 76, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 97 775496A4 13 Bytes [ 33, 8D, 45, 0C, 50, 57, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + A5 775496B2 429 Bytes [ 25, 0F, B7, 45, 0C, 50, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoUnloadingWOW + 253 77549860 151 Bytes [ 75, 0C, 53, 68, 12, 01, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 7 77549FAD 88 Bytes [ 88, 50, 8D, 4B, FC, E8, 22, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 60 7754A006 22 Bytes [ 83, 63, 50, FE, B8, 71, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 77 7754A01D 5 Bytes [ 04, 80, E9, 2C, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + 7E 7754A024 59 Bytes [ F6, 43, 50, 08, 0F, 85, 22, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetConvertStg + BA 7754A060 56 Bytes CALL 7759B8BD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 25 7754A625 15 Bytes [ C0, 5D, C2, 04, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 35 7754A635 66 Bytes [ 8B, 80, 80, 0F, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + 78 7754A678 47 Bytes [ 00, 00, EB, 49, 66, 83, 3E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + A8 7754A6A8 2 Bytes [ 2B, 09 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleIsCurrentClipboard + AE 7754A6AE 210 Bytes [ 89, 45, FC, 74, 12, 66, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 88 7754A839 133 Bytes [ 46, 0C, 6A, 00, 89, 45, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 10E 7754A8BF 65 Bytes [ 06, 6A, 00, FF, 75, 0C, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 150 7754A901 63 Bytes [ 7D, 08, 85, FF, 75, 04, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 190 7754A941 151 Bytes [ 07, 57, FF, 15, 04, 12, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleFlushClipboard + 228 7754A9D9 45 Bytes [ C0, 75, 09, 66, 39, 46, 0A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 35 7754B79B 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 3B 7754B7A1 2 Bytes [ FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 3E 7754B7A4 14 Bytes [ 7C, A7, 54, 77, 85, A7, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 4D 7754B7B3 65 Bytes [ 55, 8B, EC, 83, EC, 14, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEx + 8F 7754B7F5 61 Bytes [ F0, 0F, 84, 53, 01, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 38 7754B90C 81 Bytes [ 15, 74, 12, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 8A 7754B95E 28 Bytes [ 18, 4B, 77, 85, C0, 75, 09, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + A7 7754B97B 14 Bytes [ FF, 55, 8B, EC, 56, 57, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + B6 7754B98A 88 Bytes [ 15, CC, 18, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreate + 10F 7754B9E3 8 Bytes [ EB, DE, 90, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx 7754BDA1 30 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 1F 7754BDC0 18 Bytes [ 83, 7E, 74, 01, 75, 07, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 32 7754BDD3 29 Bytes [ 83, 38, 00, 74, 08, 8B, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 50 7754BDF1 72 Bytes [ 5E, 5D, C2, 04, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromDataEx + 99 7754BE3A 100 Bytes [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 2 7754BE9F 21 Bytes CALL 784243B3
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 18 7754BEB5 18 Bytes [ 53, 8D, 45, DC, 50, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 2B 7754BEC8 21 Bytes [ FF, 3B, C3, 89, 45, E8, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 41 7754BEDE 39 Bytes [ 75, E0, FF, 75, E0, FF, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromData + 71 7754BF0E 1 Byte [ 4D ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreatePointerMoniker + 40 7754C3D8 200 Bytes [ 00, 00, 8B, 4D, CC, 8D, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + A9 7754C4A1 3 Bytes [ 07, 80, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + AD 7754C4A5 70 Bytes [ B8, 3B, C3, 74, 06, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 119 7754C511 109 Bytes [ 75, B4, 8B, 46, 04, 3B, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 187 7754C57F 212 Bytes [ 08, 50, FF, 51, 08, 8B, C6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateObjrefMoniker + 25C 7754C654 27 Bytes [ FF, 15, D0, 13, 4B, 77, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 36 7754C732 32 Bytes [ 51, C7, 01, 28, E0, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 57 7754C753 19 Bytes CALL 775A535B C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 6B 7754C767 30 Bytes [ FF, 55, 8B, EC, 83, EC, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + 8A 7754C786 21 Bytes [ 85, C0, 74, 11, 6A, 04, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!BindMoniker + A0 7754C79C 108 Bytes [ 75, 30, 89, 3B, FF, 75, 2C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith 7754DE00 140 Bytes [ 90, 6A, 0C, 68, 78, CE, 54, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + 8D 7754DE8D 38 Bytes [ EC, 56, 57, 8B, 7D, 08, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + B4 7754DEB4 64 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + F5 7754DEF5 1 Byte [ E0 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!MonikerCommonPrefixWith + F7 7754DEF7 7 Bytes [ 35, 24, 12, 4B, 77, FF, D6 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 2 7754E98A 32 Bytes [ 51, 44, 8B, D8, 3B, DF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 23 7754E9AB 10 Bytes [ 45, FC, 8B, 4D, 0C, 89, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 2E 7754E9B6 91 Bytes [ 02, 33, DB, 8B, 45, F8, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 8A 7754EA12 3 Bytes [ 0C, 56, E8 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateStdProgressIndicator + 8E 7754EA16 34 Bytes [ FA, F7, FF, 85, C0, 0F, 84, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + 73 7754EB1D 37 Bytes [ 8B, 45, F4, 89, 45, F0, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + 99 7754EB43 9 Bytes [ 45, EC, 50, FF, 75, F8, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + A3 7754EB4D 12 Bytes [ FF, 8B, F8, 85, FF, 7C, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + B0 7754EB5A 27 Bytes [ 12, FF, 75, 10, FF, 75, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetClassFile + CC 7754EB76 40 Bytes [ 75, F4, 50, FF, 51, 2C, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCurrentLogicalThreadId 7755206E 50 Bytes [ 90, 90, 90, 6A, 0C, 68, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 43 775520E8 48 Bytes [ 75, 14, 33, C0, F3, A7, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 74 77552119 44 Bytes [ 04, 83, C6, 14, 89, 33, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 17A 7755221F 33 Bytes [ 50, FF, 11, 89, 45, E4, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 19C 77552241 41 Bytes [ 51, 08, EB, 21, C7, 45, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetClassVersion + 1F9 7755229E 50 Bytes [ 49, 18, 8B, 55, 0C, 89, 0A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 3 7755269F 73 Bytes [ 77, 78, 16, 55, 77, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 56 775526F2 26 Bytes [ 8B, FF, 55, 8B, EC, 5D, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 71 7755270D 15 Bytes [ 90, 90, 90, 90, 90, 83, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + 82 7755271E 58 Bytes [ 90, 90, 90, 83, 6C, 24, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTreatAsClass + BD 77552759 98 Bytes [ EB, A7, 90, 90, 90, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 1C 77552973 3 Bytes [ E0, FE, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 20 77552977 9 Bytes [ 89, 45, CC, 33, F6, 3B, C6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DllRegisterServer + 2A 77552981 100 Bytes [ 00, 00, 00, 8B, 4D, D0, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 33 775529E6 38 Bytes [ FF, 89, 45, CC, 3B, C6, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 5A 77552A0D 37 Bytes [ 7C, 40, 8B, 45, C0, 2B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + 80 77552A33 112 Bytes [ 04, 80, EB, 1F, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + F1 77552AA4 3 Bytes [ C8, 10, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterInitializeSpy + F5 77552AA8 30 Bytes [ 00, 8B, 7D, 0C, 8B, 07, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 52 77552B9F 29 Bytes [ 01, 04, 80, EB, 18, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 70 77552BBD 9 Bytes [ 4D, FC, FF, 8B, 45, D0, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeInitializeSpy + 7A 77552BC7 3 Bytes [ B5, B7, F7 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState 77552BD4 51 Bytes [ 90, 90, 90, 90, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState + 34 77552C08 14 Bytes [ 45, 18, 89, 18, C7, 45, B4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetState + 43 77552C17 91 Bytes [ 08, 8D, 55, B4, 52, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 4A 77552C73 156 Bytes [ D0, 8D, 43, 02, 83, C0, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + E7 77552D10 47 Bytes [ 10, D1, FF, 8B, 45, 14, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 11C 77552D45 17 Bytes CALL CF397311
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 137 77552D60 123 Bytes [ FF, FF, FF, FF, 3B, 1D, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryReleaseObject + 1B3 77552DDC 55 Bytes [ 90, 90, 90, 90, 90, B8, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 24 77552E63 4 Bytes [ 75, 07, B8, 57 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 29 77552E68 64 Bytes [ 07, 80, EB, 43, 83, 7D, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 6A 77552EA9 52 Bytes [ C6, EB, 03, 33, C0, 40, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + 9F 77552EDE 16 Bytes [ FF, 75, 08, FF, 15, D0, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterMallocSpy + B0 77552EEF 27 Bytes [ 06, FF, 75, 10, 8B, CE, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 1 77552F10 258 Bytes [ EC, 8B, 45, 08, 51, 68, BA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 104 77553013 4 Bytes [ FF, 55, 8B, EC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 11D 7755302C 46 Bytes [ 07, 80, 5D, C2, 08, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 20B 7755311A 48 Bytes [ 51, 08, 5F, 8B, C6, 5E, 5B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRevokeMallocSpy + 23D 7755314C 24 Bytes [ 00, 75, 20, 6A, 48, E8, 7B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 5F 77553764 18 Bytes [ BF, 28, 6C, 4C, 77, 57, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 72 77553777 6 Bytes [ 01, 56, 53, FF, 75, 94 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 79 7755377E 13 Bytes [ 15, 2C, 10, 4B, 77, 8B, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 87 7755378C 122 Bytes [ 00, 8D, 45, 8C, 50, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HkOleRegisterObject + 102 77553807 133 Bytes [ 15, 40, 10, 4B, 77, 33, F6, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject 7755398C 167 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + A8 77553A34 18 Bytes [ 00, 3B, F3, 75, 3F, 6A, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + BB 77553A47 2 Bytes [ 45, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + BE 77553A4A 34 Bytes [ 80, 08, 01, 00, 00, 89, 46, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!EnableHookObject + E1 77553A6D 17 Bytes [ F7, FF, C7, 45, 0C, 0E, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 65 77554626 61 Bytes [ FF, 55, 8B, EC, FF, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + A3 77554664 58 Bytes [ 07, 80, EB, 31, 57, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + DF 775546A0 85 Bytes [ 90, 90, 90, A1, A8, C5, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 135 775546F6 9 Bytes [ E0, B8, 02, 40, 00, 80, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetStdMarshalEx + 13F 77554700 8 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDeactivateObject + 5A 7755489F 65 Bytes [ 0F, 85, C3, 00, 00, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 9 775548E1 39 Bytes CALL C85548E4
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 31 77554909 33 Bytes [ 74, 5D, 56, 8B, 35, 28, 12, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 53 7755492B 28 Bytes [ D6, 68, F0, 8A, 4C, 77, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoReactivateObject + 70 77554948 106 Bytes [ 77, A3, AC, C5, 5D, 77, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInvalidateRemoteMachineBindings + 2 775549B3 5 Bytes [ FF, 00, 80, 5D, C2 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInvalidateRemoteMachineBindings + 9 775549BA 35 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRetireServer + 9 775549DE 20 Bytes [ 72, 5D, 77, 8B, F0, 8D, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRetireServer + 1E 775549F3 9 Bytes [ 75, 16, 83, C6, 08, 3B, F0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetContextToken + 1 77554A25 40 Bytes [ 48, 0C, 83, C0, 20, 3B, C8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetContextToken + 2A 77554A4E 55 Bytes [ 4D, FC, 6A, 01, 83, C1, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetSystemSecurityPermissions + 2B 77554A86 14 Bytes [ 60, 5D, 77, FF, 15, 54, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetSystemSecurityPermissions + 3A 77554A95 77 Bytes [ 75, 0C, 89, 43, 0C, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 3A 77554AE3 77 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 89 77554B32 33 Bytes [ 00, 53, 56, 89, 45, FC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + AB 77554B54 27 Bytes [ FF, 50, FF, 15, C0, 18, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + C7 77554B70 23 Bytes [ CB, 89, 85, EC, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetDefaultContext + 10D 77554BB6 8 Bytes [ FF, 50, 57, 8B, CE, E8, 86, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetCancelObject + 7B 775550ED 79 Bytes [ FF, 55, 8B, EC, 68, A8, BA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCancelCall + 35 7755513D 49 Bytes [ FF, 55, 8B, EC, 56, 68, AC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTestCancel + 27 7755516F 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoTestCancel + 2A 77555172 71 Bytes [ EC, 56, 68, B0, BA, 5D, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoEnableCallCancellation + 39 775551BA 5 Bytes [ 25, B8, BA, 5D, 77 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoEnableCallCancellation + 40 775551C1 1 Byte [ 08 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 5 775551CD 80 Bytes [ 68, BC, BA, 5D, 77, 68, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 56 7755521E 19 Bytes [ F0, 8B, C6, 5E, 5D, C2, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 6A 77555232 3 Bytes [ E4, BA, 5D ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 6E 77555236 6 Bytes [ 68, 70, 8C, 4C, 77, 33 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDisableCallCancellation + 81 77555249 6 Bytes [ FF, 75, 0C, FF, 75, 08 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 8 77555626 122 Bytes [ 08, 50, FF, 51, 04, EB, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 83 775556A1 19 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + 97 775556B5 10 Bytes [ 08, 50, FF, 51, 0C, EB, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + A2 775556C0 41 Bytes [ 80, 5D, C2, 08, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoSetCancelObject + CC 775556EA 269 Bytes [ 80, 5D, C2, 08, 00, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + 37 775558A8 113 Bytes [ 8B, 06, 56, FF, 50, 08, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + A9 7755591A 22 Bytes [ 00, 8B, F0, 8B, 45, 0C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + C0 77555931 37 Bytes [ 08, 50, FF, 51, 08, EB, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + E6 77555957 24 Bytes [ 57, 8B, 7D, 08, 33, F6, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoQueryAuthenticationServices + FF 77555970 29 Bytes [ 07, 8D, 4D, FC, 51, 68, 18, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 29 77559AAD 2 Bytes [ 0E, 47 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 2D 77559AB1 188 Bytes [ 39, 7D, F0, 0F, 84, BB, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + EA 77559B6E 27 Bytes [ F7, FF, 39, 7D, FC, 7D, 65, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 107 77559B8B 6 Bytes [ 45, EC, 3B, C7, 74, 0F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoCreateObjectInContext + 10E 77559B92 36 Bytes [ 08, 50, FF, 51, 10, 8B, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + BA 7755B46D 34 Bytes [ 08, 83, 65, F8, 00, 8D, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + DD 7755B490 42 Bytes [ 51, 10, 8B, F0, 8B, 45, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 108 7755B4BB 26 Bytes [ 8B, 45, F4, 83, C0, 07, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 123 7755B4D6 12 Bytes [ 8D, 6E, FF, FF, FF, 85, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetApartmentID + 130 7755B4E3 54 Bytes [ 4D, FC, 89, 08, 8B, C6, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterPSClsid + 94 7755C75C 34 Bytes [ 8B, F0, 85, F6, 0F, 8C, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPushServiceDomain + 13 7755C77F 51 Bytes [ FF, 8B, F0, 85, F6, 0F, 8C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + C 7755C7B3 20 Bytes [ 89, 55, E0, 89, 7D, E4, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 21 7755C7C8 66 Bytes [ 15, FC, 12, 4B, 77, 57, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 64 7755C80B 18 Bytes [ 50, 10, 8B, F0, 8B, 45, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 77 7755C81E 35 Bytes [ 45, B4, 8B, 40, 24, 57, 23, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoPopServiceDomain + 9B 7755C842 8 Bytes [ 4D, B4, 8D, 45, 9C, 89, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 4F 7755E25D 4 Bytes [ 68, 30, 75, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 54 7755E262 31 Bytes [ FF, 76, 30, FF, D7, BB, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 74 7755E282 3 Bytes [ 00, 00, 51 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 79 7755E287 137 Bytes [ 15, A8, 10, 4B, 77, B9, CC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogateEx + 104 7755E312 148 Bytes [ 68, 20, 4E, 00, 00, FF, 76, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 10 7755F5A2 66 Bytes [ 40, 18, 83, 65, FC, 00, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 53 7755F5E5 41 Bytes [ 15, 34, 12, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 7D 7755F60F 28 Bytes [ 55, 8B, EC, 8B, 45, 08, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + 9A 7755F62C 43 Bytes [ 15, 24, 12, 4B, 77, 0D, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UpdateDCOMSettings + C6 7755F658 27 Bytes [ 09, 89, 48, 14, 33, C0, EB, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 8A 775661D6 1 Byte [ 4A ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 8D 775661D9 8 Bytes [ 0C, 8B, 4F, 10, E8, 3B, E2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 96 775661E2 8 Bytes [ 8B, CE, 8B, D8, E8, D4, 7F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoRegisterSurrogate + 9F 775661EB 60 Bytes [ 85, DB, 7C, 1F, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInstanceFromIStorage + B 77566228 49 Bytes [ 8B, 45, 14, 8B, 4D, FC, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoLoadLibrary + 13 7756625A 55 Bytes [ 77, 00, 75, 51, 33, FF, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + E2 775663C9 3 Bytes [ 21, 34, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + E6 775663CD 6 Bytes [ FF, 75, 08, 83, 66, 14 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + ED 775663D4 67 Bytes [ FF, 75, 08, 8B, CE, E8, 67, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + 131 77566418 140 Bytes [ 3B, 89, 4B, 14, 8B, 36, F3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoInstall + 1BE 775664A5 40 Bytes [ 50, FF, 15, 40, 12, 4B, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoFileTimeToDosDateTime + 78 7756B0CF 64 Bytes [ FD, FF, FF, 00, 8D, 8D, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 3D 7756B110 38 Bytes [ 02, 00, 00, B9, 82, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 64 7756B137 42 Bytes [ 15, 84, 13, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + 8F 7756B162 27 Bytes [ 00, 8D, 44, 00, 18, 50, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + AB 7756B17E 2 Bytes [ 51, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoDosDateTimeToFileTime + AF 7756B182 2 Bytes [ DC, 14 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 10 7757016C 51 Bytes [ 90, 8B, FF, 55, 8B, EC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 44 775701A0 305 Bytes [ 8B, 08, 68, A4, FF, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 176 775702D2 23 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 18E 775702EA 104 Bytes [ FF, 75, 10, 8B, 08, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CoGetInterceptor + 1F7 77570353 20 Bytes [ 00, 74, 11, FF, 75, 10, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_QueryInterface 77570529 5 Bytes [ 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_QueryInterface + 6 7757052F 113 Bytes [ 55, 8B, EC, 51, 53, 56, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 2 775705A1 3 Bytes [ 8B, 45, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 6 775705A5 18 Bytes [ 08, 89, 4F, 08, 89, 38, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_DebugServerQueryInterface + 1C 775705BB 116 Bytes [ 8B, FF, 55, 8B, EC, 51, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_CountRefs + 7 77570631 5 Bytes [ FC, 8B, 08, 89, 4F ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_CStdStubBuffer_CountRefs + D 77570637 21 Bytes [ 89, 38, 8B, 3F, 3B, FB, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 9 7757064D 33 Bytes [ EC, 56, 57, 8B, 7D, 08, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 2B 7757066F 1 Byte [ 57 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 56 7757069A 65 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + 98 775706DC 53 Bytes [ 55, 14, 85, D2, 74, 14, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubForwardingFunction + CE 77570712 14 Bytes [ 40, 1C, 8B, 40, 24, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 25 77570953 86 Bytes JMP 02FCFC5A
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 7C 775709AA 100 Bytes [ 46, FC, 50, 8B, 46, 18, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + E1 77570A0F 47 Bytes [ 8D, 8D, 6C, FF, FF, FF, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 120 77570A4E 12 Bytes [ 51, 08, 83, 65, E4, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_IUnknown_Release_Proxy + 12F 77570A5D 29 Bytes [ 8B, 47, 08, 89, 45, 80, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + F 775745F4 99 Bytes [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + A6 7757468B 24 Bytes [ 90, 90, 90, 90, 90, B8, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 100 775746E5 13 Bytes [ 90, 90, 90, 90, 90, B8, 07, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 10E 775746F3 174 Bytes [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2_va + 1F0 775747D5 23 Bytes [ 90, 90, 90, 90, 90, B8, 17, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 1B 77574AA8 206 Bytes [ 90, 90, B8, 47, 03, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + EA 77574B77 14 Bytes [ 90, 90, 90, 90, 90, B8, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + F9 77574B86 63 Bytes [ 90, 90, 90, 90, 90, B8, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 13A 77574BC7 41 Bytes [ B8, 5A, 03, 00, 00, E9, CC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrClientCall2 + 167 77574BF4 25 Bytes [ B8, 5D, 03, 00, 00, E9, 9F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject 775751D0 98 Bytes [ B8, C1, 03, 00, 00, E9, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 63 77575233 14 Bytes [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 72 77575242 31 Bytes [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + 93 77575263 71 Bytes [ 90, 90, 90, B8, CB, 03, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllGetClassObject + DB 775752AB 15 Bytes [ FF, 90, 90, 90, 90, 90, B8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllUnregisterProxy + 6 77575F1A 31 Bytes [ FF, F6, 45, 08, 01, 74, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrDllUnregisterProxy + 61 77575F75 54 Bytes [ 8B, FF, 55, 8B, EC, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 34 77575FAC 41 Bytes [ 5D, 0C, 85, DB, 56, 57, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 5E 77575FD6 19 Bytes [ 5B, 5D, C2, 0C, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 8E 77576006 15 Bytes [ 51, 0C, 5E, 5D, C2, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + 9E 77576016 61 Bytes [ EC, 56, 8B, 75, 08, 56, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!ComPs_NdrStubCall2 + DC 77576054 12 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserSize + 57 77589980 137 Bytes [ A1, 04, 60, 5D, 77, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + 61 77589A0A 66 Bytes [ 32, 02, 00, 00, 8D, 85, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + A4 77589A4D 50 Bytes CALL 7758991A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + D7 77589A80 23 Bytes [ 85, 7C, FB, FF, FF, 89, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + EF 77589A98 95 Bytes [ F4, 6C, 4C, 77, BE, A8, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserMarshal + 14F 77589AF8 49 Bytes [ FF, 68, 28, 99, 4C, 77, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + B 77589B44 36 Bytes CALL 77589719 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 30 77589B69 5 Bytes [ 89, 85, 50, FB, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 36 77589B6F 6 Bytes [ 68, C0, 98, 4C, 77, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 3D 77589B76 87 Bytes [ D6, 8B, 85, 7C, FB, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserUnmarshal + 95 77589BCE 51 Bytes CALL 77589719 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserFree + 34 77589D4C 17 Bytes [ 10, 4B, 77, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILEPICT_UserFree + 46 77589D5E 42 Bytes [ B5, 74, FB, FF, FF, FF, D6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HENHMETAFILE_UserUnmarshal + 11 77589D89 177 Bytes [ FF, FF, FF, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + C 77589E3B 10 Bytes CALL 775898B9 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 17 77589E46 66 Bytes [ 5B, 18, 3B, DE, 74, 40, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 5A 77589E89 33 Bytes [ 50, EB, 05, 68, 6C, EE, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserMarshal + 7D 77589EAC 60 Bytes [ 00, 33, C0, 8B, 4D, E4, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserUnmarshal + 12 77589EE9 134 Bytes [ 8B, 00, 8B, 70, 14, 6A, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HMETAFILE_UserUnmarshal + 99 77589F70 88 Bytes [ 10, FD, FF, FF, 33, DB, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserSize + 2 77589FC9 144 Bytes JMP 7758A89A C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 4B 7758A05A 111 Bytes [ B5, 14, FD, FF, FF, E8, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + BB 7758A0CA 83 Bytes [ 89, 8D, 5C, FC, FF, FF, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 10F 7758A11E 109 Bytes [ 15, 20, 14, 4B, 77, 8D, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 17D 7758A18C 10 Bytes [ 0F, 84, 26, 01, 00, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserMarshal + 189 7758A198 150 Bytes JMP 7758A26D C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserUnmarshal + B 7758A22F 39 Bytes [ FF, FF, 15, 40, 10, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HPALETTE_UserUnmarshal + 33 7758A257 20 Bytes [ EB, 06, 8B, 3D, 24, 12, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!HBITMAP_UserFree + 2 7758A26C 40 Bytes [ FF, FF, 15, 40, 10, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 1 7758A295 21 Bytes [ 85, 10, FD, FF, FF, FF, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 17 7758A2AB 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 19 7758A2AD 9 Bytes [ BE, 6C, EE, 4B, 77, 8B, 3D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserSize + 24 7758A2B8 38 Bytes [ 89, 9D, A0, FC, FF, FF, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 2 7758A2DF 63 Bytes [ 89, 9D, FC, FC, FF, FF, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 42 7758A31F 5 Bytes [ 4B, 77, 89, 85, CC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 48 7758A325 3 Bytes [ FF, FF, 3B ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserMarshal + 4C 7758A329 81 Bytes [ 75, 31, FF, B5, E4, FC, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 2 7758A37B 15 Bytes [ D7, 25, FF, FF, 00, 00, 0D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 12 7758A38B 171 Bytes [ 39, 9D, FC, FC, FF, FF, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + BE 7758A437 63 Bytes [ C8, FC, FF, FF, 3B, C3, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + FE 7758A477 69 Bytes [ B5, F4, FC, FF, FF, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserUnmarshal + 145 7758A4BE 4 Bytes [ 89, 85, 60, FC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 2 7758A4DD 23 Bytes [ FF, 50, 8D, 85, 0C, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 1A 7758A4F5 78 Bytes [ B5, 18, FD, FF, FF, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 6B 7758A546 11 Bytes [ 15, 40, 10, 4B, 77, FF, D7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 77 7758A552 154 Bytes [ D7, EB, 0C, FF, D7, 25, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SNB_UserFree + 112 7758A5ED 70 Bytes [ B5, 18, FD, FF, FF, FF, 15, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLockRunning + D 77598833 8 Bytes [ 77, 3B, C3, 0F, 84, C1, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleLockRunning + 16 7759883C 131 Bytes [ 66, 8B, 48, 02, 0F, B7, D1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetContainedObject + 4E 775988CA 159 Bytes [ FF, B6, 84, 00, 00, 00, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + 9C 7759896B 11 Bytes [ 50, FF, 11, 3B, C3, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + AA 77598979 53 Bytes [ 8B, 45, F8, FF, 37, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + E0 775989AF 12 Bytes [ FF, 89, 45, FC, EB, 4F, 39, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + ED 775989BC 135 Bytes CALL 77595733 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleNoteObjectVisible + 175 77598A44 9 Bytes [ 10, 8B, F1, FF, 15, 74, 12, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetDocumentBitStg 77598BC1 47 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!SetDocumentBitStg + B 77598BF1 34 Bytes [ 83, C1, 08, 3B, CA, 72, F4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!GetConvertStg 77598C14 44 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 1 77598C41 108 Bytes [ F0, EB, 02, 33, F6, 3B, F3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 6E 77598CAE 91 Bytes [ 08, 8D, 5E, 20, 53, 68, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + CA 77598D0A 29 Bytes [ 33, DB, 8B, 46, 1C, 8B, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + E8 77598D28 105 Bytes [ 30, 89, 5D, 10, 8B, 45, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDraw + 152 77598D92 106 Bytes [ 7E, 3C, 89, 45, FC, 8B, 07, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 75 77598F77 6 Bytes [ EB, 0A, C7, 85, 00, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 7C 77598F7E 24 Bytes [ FF, 0E, 00, 07, 80, 85, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 121 77599023 19 Bytes [ 04, FF, FF, FF, 00, EB, 12, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 135 77599037 8 Bytes [ 15, D8, 13, 4B, 77, 0F, B7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleDuplicateData + 13E 77599040 21 Bytes [ 8D, 00, FF, FF, FF, C1, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData 7759968A 78 Bytes [ 90, 8B, FF, 55, 8B, EC, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 4F 775996D9 29 Bytes [ 0D, 8B, 45, 10, 83, 20, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 6D 775996F7 5 Bytes [ 5F, 5E, 5D, C2, 0C ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 73 775996FD 16 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateStaticFromData + 84 7759970E 246 Bytes [ 85, C0, 74, 12, 8B, 55, 08, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkEx + 7C 77599B6A 130 Bytes [ 4D, FC, 51, 57, 6A, 10, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 21 77599BED 45 Bytes [ 0C, F7, D8, 1B, C0, 83, E0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 4F 77599C1B 31 Bytes [ 08, 50, 8B, 45, 08, E8, 22, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 6F 77599C3B 20 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 84 77599C50 14 Bytes [ 85, C0, 75, 07, BE, 57, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFileEx + 93 77599C5F 4 Bytes [ 14, 74, 18, E8 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + E 77599D9E 42 Bytes [ E1, 03, F3, A4, 8B, 4D, DC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 39 77599DC9 4 Bytes [ 4D, 20, 8B, 11 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 3E 77599DCE 2 Bytes [ 50, 20 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 41 77599DD1 78 Bytes [ 49, 04, 89, 48, 24, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFileEx + 90 77599E20 6 Bytes [ 56, 8D, 8D, F0, FE, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 4 7759A0B4 2 Bytes [ 08, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 7 7759A0B7 2 Bytes [ 51, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + A 7759A0BA 36 Bytes [ 45, E4, 85, C0, 74, 06, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLink + 2F 7759A0DF 53 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 1A 7759A115 20 Bytes [ 0D, FF, B5, E4, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 2F 7759A12A 22 Bytes CALL C859A12C
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateLinkToFile + 46 7759A141 6 Bytes [ 00, 8D, 85, FC, FD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 2 7759A148 40 Bytes CALL C859A14A
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 86 7759A1CC 7 Bytes [ 33, C9, 41, 3B, C1, 75, 64 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 8E 7759A1D4 123 Bytes [ 75, 0C, 3B, F7, 74, 48, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 10A 7759A250 12 Bytes [ 55, 8B, EC, 56, 33, F6, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateFromFile + 117 7759A25D 3 Bytes [ 45, 08, 8B ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 4 7759BFBF 27 Bytes [ 4E, 58, 8D, 45, F8, 50, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 20 7759BFDB 51 Bytes [ 24, 83, 78, 1C, FF, 75, 1E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 55 7759C010 7 Bytes [ 8B, C7, F7, D0, 21, 46, 68 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 5D 7759C018 1 Byte [ 5D ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!CreateDataCache + 5F 7759C01A 8 Bytes [ 74, 08, 57, 8B, CE, E8, EA, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 37 775A03D8 18 Bytes [ 8B, F8, 85, FF, 0F, 85, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 4A 775A03EB 71 Bytes [ 05, 9B, 00, 00, 8B, F8, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + 92 775A0433 36 Bytes [ 8B, F8, 83, 3B, 08, 75, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + B7 775A0458 12 Bytes [ F8, 8B, 06, 89, 41, 08, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!DoDragDrop + C4 775A0465 6 Bytes [ 51, 08, 83, 65, A4, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEmbeddingHelper + 3A 775A1AC9 9 Bytes [ 0C, 0F, 94, C1, 8B, C1, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleCreateEmbeddingHelper + 44 775A1AD3 398 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + 6C 775A1C62 25 Bytes [ 76, 3C, FF, 75, F0, FF, D3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + 86 775A1C7C 30 Bytes [ D3, A8, 03, 74, 4F, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + A5 775A1C9B 50 Bytes [ 15, A8, 17, 4B, 77, 83, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + D8 775A1CCE 12 Bytes [ FF, FF, 83, 7D, 08, 00, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleSetAutoConvert + E5 775A1CDB 30 Bytes [ 00, 00, 33, C0, 40, 5B, 5F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 1A 775A2759 15 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 2A 775A2769 66 Bytes CALL 77503EB6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 6D 775A27AC 45 Bytes [ 0F, 94, C1, 51, 56, FF, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + 9B 775A27DA 75 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleMetafilePictFromIconAndLabel + E7 775A2826 23 Bytes [ 85, C0, 75, 07, B8, 0E, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + A 775A2C01 92 Bytes [ A1, 04, 60, 5D, 77, 83, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 67 775A2C5E 2 Bytes [ FC, FB ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 78 775A2C6F 17 Bytes [ 50, FF, 15, 20, 14, 4B, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + 8A 775A2C81 34 Bytes [ B8, EF, 4B, 77, FF, B5, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfFile + AD 775A2CA4 5 Bytes [ FF, 00, 5B, 74, 0C ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + 57 775A2F38 24 Bytes [ F6, 74, 07, 33, F6, E9, 46, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + 71 775A2F52 58 Bytes [ 15, 7C, 13, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + AC 775A2F8D 7 Bytes [ FF, 8D, 85, 7C, FF, FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + B4 775A2F95 9 Bytes [ FF, 15, 78, 12, 4B, 77, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleGetIconOfClass + BE 775A2F9F 2 Bytes [ FF, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 2D 775A3D7E 15 Bytes [ FF, FF, D3, 8D, 85, 88, FA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 3D 775A3D8E 117 Bytes [ 50, FF, 35, 2C, 61, 5D, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + B3 775A3E04 97 Bytes [ FA, FF, FF, 8D, 44, 46, FE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 115 775A3E66 12 Bytes [ 50, 8D, 85, 54, FF, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleRegEnumFormatEtc + 122 775A3E73 10 Bytes [ 68, 00, 00, 00, 80, C7, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 29 775A9645 17 Bytes [ 55, 8B, EC, 81, EC, AC, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 3B 775A9657 3 Bytes [ 53, 33, DB ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 3F 775A965B 1 Byte [ 55 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAM + 41 775A965D 91 Bytes [ 52, 53, 53, 89, 45, FC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + 42 775A96B9 148 Bytes [ 75, B4, FF, 15, 20, 14, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + D7 775A974E 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + D9 775A9750 9 Bytes [ 5D, B0, 6A, 04, 33, C0, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + E3 775A975A 3 Bytes [ B2, EF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertIStorageToOLESTREAMEx + E9 775A9760 9 Bytes [ 89, 45, AC, 0F, 8C, 01, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 14 775A9976 59 Bytes CALL 775917AD C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 50 775A99B2 14 Bytes [ 55, 8B, EC, 83, 7D, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorage + 5F 775A99C1 69 Bytes [ 00, 8B, 03, 85, C0, 75, 0A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4 775A9A07 14 Bytes [ F8, 85, FF, 75, 07, B8, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4B 775A9A4E 2 Bytes [ D2, 45 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 4F 775A9A52 30 Bytes [ 8B, C6, 5E, 5F, 5D, C2, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 6E 775A9A71 5 Bytes [ FF, 85, C0, 74, 09 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!OleConvertOLESTREAMToIStorageEx + 74 775A9A77 160 Bytes CALL 775A8CE0 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd16Info + 1B 775AA719 205 Bytes [ F0, 85, F6, 0F, 85, B8, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd16Info + 113 775AA811 30 Bytes [ 85, C0, 0F, 8C, 12, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 8 775AA830 148 Bytes [ FF, 03, 75, 0F, 8B, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 9D 775AA8C5 25 Bytes [ 01, 75, 4B, 83, 65, F8, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + B7 775AA8DF 68 Bytes CALL 775A99AF C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + FC 775AA924 45 Bytes CALL 775AA306 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd16toDvtd32 + 12A 775AA952 63 Bytes CALL 775AA7F6 C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1 775AAA1A 5 Bytes [ 45, 0C, 89, 45, 94 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 7 775AAA20 20 Bytes [ 45, 10, 53, 8B, 5D, 1C, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1C 775AAA35 1 Byte [ 7D ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 1E 775AAA37 9 Bytes [ 8D, 4D, A8, 89, 45, 98, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtGetDvtd32Info + 28 775AAA41 75 Bytes [ E2, FF, FF, 39, 75, A0, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 30 775AAB59 150 Bytes [ 4E, 1C, 8B, 55, 9C, 89, 0A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + FD 775AAC26 41 Bytes [ 06, 56, FF, 50, 0C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 127 775AAC50 18 Bytes [ 6A, 01, FF, 75, F0, E8, A0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 13A 775AAC63 71 Bytes [ F8, 7F, 05, 0E, 00, 07, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!UtConvertDvtd32toDvtd16 + 182 775AACAB 4 Bytes [ 8B, 45, EC, 83 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 3F 775AC07F 19 Bytes [ 15, 00, 12, 4B, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 53 775AC093 174 Bytes [ 00, 50, 6A, 02, FF, 15, D0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 102 775AC142 21 Bytes [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 118 775AC158 180 Bytes [ 89, 5D, F8, 89, 5D, E8, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenStorageOnILockBytes + 1CD 775AC20D 28 Bytes [ 15, 94, 11, 4B, 77, 89, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 10 775AC3A5 9 Bytes [ 1F, 39, 5D, FC, 74, 09, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 1A 775AC3AF 110 Bytes [ 15, CC, 13, 4B, 77, 39, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 89 775AC41E 125 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 107 775AC49C 9 Bytes [ 99, F7, 7E, 18, 8B, 4D, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgIsStorageILockBytes + 111 775AC4A6 27 Bytes [ 46, 08, 69, C0, A0, 86, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantChangeType + 32 775B3A19 118 Bytes [ 0E, 00, 07, 80, EB, 13, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantChangeType + A9 775B3A90 30 Bytes [ 45, 08, 83, C0, 08, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + 2 775B3AAF 11 Bytes [ 8B, F0, 83, 7D, FC, 00, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + E 775B3ABB 2 Bytes [ 65, A5 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!FmtIdToPropStgName + 12 775B3ABF 104 Bytes [ 8B, C6, 5E, C9, C2, 0C, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropStgNameToFmtId + 39 775B3B46 14 Bytes [ 0C, 8D, 45, EC, 50, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropStgNameToFmtId + 48 775B3B55 33 Bytes [ FF, 15, FC, BA, 5D, 77, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 19 775B3B82 39 Bytes [ 74, 09, FF, 75, FC, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 41 775B3BAA 4 Bytes [ 83, A5, F8, FC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + 46 775B3BAF 150 Bytes [ FF, 00, 53, 8B, 5D, 08, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropStg + DD 775B3C46 224 Bytes JMP 6B53C74D
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenPropStg + 3D 775B3D27 40 Bytes [ 47, 83, F8, 15, 74, 0F, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenPropStg + 66 775B3D50 752 Bytes [ EB, 31, FF, 75, 18, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 1F5 775B4041 32 Bytes [ 50, FF, 75, F8, 56, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 216 775B4062 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgCreatePropSetStg + 219 775B4065 67 Bytes [ EC, 51, 51, 8B, 4D, 0C, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 9 775B40A9 129 Bytes [ 48, 0F, 84, 2F, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + F5 775B4195 6 Bytes [ 84, 9F, 00, 00, 00, 48 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + FC 775B419C 11 Bytes [ 6B, 48, 74, 12, 48, 48, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 108 775B41A8 8 Bytes [ 48, 74, 34, 48, 0F, 85, CC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropSysFreeString + 111 775B41B1 6 Bytes [ 00, 3B, F7, 0F, 8F, 61 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 9 775B42D3 2 Bytes [ 01, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + C 775B42D6 36 Bytes [ 83, F9, 1E, 0F, 8D, 6A, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 32 775B42FC 106 Bytes [ 00, 49, 0F, 84, 98, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + 9D 775B4367 36 Bytes [ 00, 00, 8B, 4D, 08, 89, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!PropVariantCopy + C2 775B438C 15 Bytes [ 00, 00, DF, 6D, F8, 8B, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgPropertyLengthAsVariant + 1F 775B5DD2 88 Bytes [ 0F, 8C, 1B, 02, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 40 775B5E2B 87 Bytes [ 8A, 45, 20, 88, 45, DB, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 99 775B5E84 12 Bytes [ 3B, C1, 0F, 8F, 9E, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + A6 775B5E91 89 Bytes [ 00, 83, C1, F6, 3B, C1, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 100 775B5EEB 55 Bytes [ 80, 7D, 20, 00, 0F, 85, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgConvertPropertyToVariant + 138 775B5F23 45 Bytes [ 46, 08, 5F, EB, 64, 8A, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 3A 775C056E 14 Bytes [ 0F, 86, 3C, 02, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 49 775C057D 39 Bytes [ 00, 8D, 04, 40, 8D, 3C, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 71 775C05A5 40 Bytes [ 74, 0E, 8B, 45, 10, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + 9A 775C05CE 26 Bytes [ 83, 3E, 00, 0F, 8C, 4B, 07, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnILockBytes + B5 775C05E9 19 Bytes [ FF, FF, 8B, 45, 14, FF, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 2 775C05FD 15 Bytes [ 8B, 45, 14, FF, 30, E8, 5F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 12 775C060D 85 Bytes [ FF, FF, 8B, 0F, 83, F9, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 69 775C0664 1 Byte [ DC ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 6B 775C0666 32 Bytes CALL 7750CDAF C:\WINDOWS\system32\ole32.dll (Microsoft OLE per Windows/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgOpenAsyncDocfileOnIFillLockBytes + 8C 775C0687 1 Byte [ 55 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 48 775C07F0 205 Bytes [ 8B, CF, 8B, 7D, E4, 8B, D1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 17E 775C0926 43 Bytes [ FC, 83, 45, E4, 10, 83, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1AB 775C0953 43 Bytes [ 83, 3E, 00, 89, 45, 1C, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1D7 775C097F 26 Bytes [ 45, F4, 8B, 40, 04, 83, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] ole32.dll!StgGetIFillLockBytesOnFile + 1F2 775C099A 69 Bytes [ 45, F4, 8B, 40, 04, 03, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF827F3 77A5153D 11 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82802 77A5154C 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82831 77A5157B 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF82841 77A5158B 96 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + FFF828A2 77A515EC 5 Bytes [ 00, 00, 00, 00, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFlushLruCache + 12 77A542DD 614 Bytes [ 43, 72, 79, 70, 74, 45, 6E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + F5 77A54544 10 Bytes [ 74, 43, 6F, 6E, 74, 65, 78, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 100 77A5454F 8 Bytes [ 79, 70, 74, 49, 6E, 73, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 109 77A54558 8 Bytes [ 6C, 4F, 49, 44, 46, 75, 6E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 112 77A54561 33 Bytes [ 69, 6F, 6E, 41, 64, 64, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallAsn1Module + 134 77A54583 26 Bytes [ 6C, 6F, 63, 00, 43, 72, 79, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 3A 77A54CC0 329 Bytes [ 6E, 63, 6F, 64, 65, 72, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 184 77A54E0A 54 Bytes [ 49, 5F, 43, 72, 79, 70, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1BB 77A54E41 15 Bytes [ 54, 6C, 73, 00, 49, 5F, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1CB 77A54E51 35 Bytes [ 4C, 72, 75, 45, 6E, 74, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRegisterSmartCardStore + 1EF 77A54E75 553 Bytes [ 49, 5F, 43, 72, 79, 70, 74, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL 77A5528D 28 Bytes [ 90, C2, 00, 00, 59, E9, 9E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 1D 77A552AA 50 Bytes [ 76, 14, 8B, 46, 34, 83, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 50 77A552DD 11 Bytes [ FF, 75, 10, 8B, CE, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 5C 77A552E9 14 Bytes [ FF, F6, 06, 01, 0F, 84, 8E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgSignCTL + 6B 77A552F8 31 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 21 77A56BC5 13 Bytes [ FF, FF, 3B, C6, A3, 20, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 44 77A56BE8 35 Bytes JMP 0377A960
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 68 77A56C0C 197 Bytes [ 2C, 69, A9, 77, 07, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 12E 77A56CD2 7 Bytes [ 00, 00, 29, 6E, A9, 77, 20 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetIntendedKeyUsage + 136 77A56CDA 169 Bytes [ 00, 00, 7C, 7B, A9, 77, 21, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet 77A57A0D 10 Bytes [ 67, A5, 77, 08, B8, A8, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + B 77A57A18 11 Bytes [ 08, B8, A8, 77, 80, 67, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 17 77A57A24 23 Bytes [ 10, 46, A5, 77, 3B, B8, A8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 2F 77A57A3C 23 Bytes [ 90, 67, A5, 77, 8E, C2, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInitOIDFunctionSet + 47 77A57A54 76 Bytes [ 10, 46, A5, 77, F8, B8, A8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + F4 77A57BB3 113 Bytes [ 6C, 33, DB, FF, 77, 68, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 166 77A57C25 148 Bytes [ D9, 72, 03, 8B, 5D, 14, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 1FB 77A57CBA 104 Bytes [ 70, 68, 33, DB, 68, 18, 6D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 265 77A57D24 58 Bytes [ 32, 2E, 35, 2E, 32, 39, 2E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallOIDFunctionAddress + 2A0 77A57D5F 88 Bytes [ 00, 3B, FB, 0F, 84, 96, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + 5 77A5833B 40 Bytes [ FF, D3, 39, 7D, FC, 74, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + 2E 77A58364 117 Bytes [ D3, 39, 7D, DC, 74, 05, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + A4 77A583DA 13 Bytes [ 00, 85, C0, 0F, 84, 4E, D3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + C4 77A583FA 28 Bytes [ 90, 90, 01, 00, 00, 00, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStoreLocation + E1 77A58417 71 Bytes [ 00, 41, 30, A9, 77, 05, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + 6 77A59BDE 144 Bytes [ A5, 77, FF, 35, 20, 53, AD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + 98 77A59C70 28 Bytes [ 85, C0, 74, 1D, 57, 68, A0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionAddress + B5 77A59C8D 301 Bytes [ 04, 8C, FF, FF, 33, C0, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFreeOIDFunctionAddress + 4B 77A59DBC 174 Bytes [ 64, D2, A9, 77, 78, 7E, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProv + 59 77A59E6B 135 Bytes [ 00, 89, 31, AA, 77, 18, 6D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 84 77A59EF4 1 Byte [ 35 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 86 77A59EF6 16 Bytes [ AA, 77, 0B, 00, 00, 00, 35, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + 98 77A59F08 34 Bytes [ 23, 00, 00, 00, 2F, 6E, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + BC 77A59F2C 19 Bytes [ 26, 03, AA, 77, E0, 47, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuid + D0 77A59F40 62 Bytes [ D8, 48, A5, 77, 26, 03, AA, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 6B 77A5A388 39 Bytes [ 00, 00, 6A, 02, 56, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 93 77A5A3B0 130 Bytes [ D6, 85, C0, 74, 72, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 117 77A5A434 70 Bytes [ E0, FF, D6, 39, 5D, E4, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryInfoKeyU + 15E 77A5A47B 21 Bytes [ FF, 8B, F0, 85, F6, 0F, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenHKCUKeyExU 77A5A494 10 Bytes [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + 90 77A5A550 3 Bytes [ 32, 00, 5C ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + 94 77A5A554 17 Bytes [ 50, 00, 65, 00, 72, 00, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + A6 77A5A566 1 Byte [ 63 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + A8 77A5A568 68 Bytes [ 65, 00, 00, 00, 68, 80, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegOpenKeyExU + EE 77A5A5AE 47 Bytes [ 90, 90, 90, FF, 25, C0, 11, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 2 77A5A78F 136 Bytes [ FF, 39, 5E, 14, 74, B9, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 8B 77A5A818 17 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 9D 77A5A82A 73 Bytes [ 00, 33, C0, 39, 45, 0C, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + E7 77A5A874 33 Bytes [ 00, 8B, 07, 85, C0, 74, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReadTrustedPublisherDWORDValueFromRegistry + 109 77A5A896 37 Bytes [ FF, D0, 85, C0, 0F, 85, AE, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 1 77A5AA76 9 Bytes [ 46, 0C, 85, C0, 0F, 85, E6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + B 77A5AA80 8 Bytes [ 3B, 35, 2C, 51, AD, 77, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 14 77A5AA89 39 Bytes [ 46, 08, A3, 2C, 51, AD, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 70 77A5AAE5 33 Bytes [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDFunction + 93 77A5AB08 16 Bytes [ F6, 47, 2A, 04, FF, 76, 04, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 12 77A5B0FE 22 Bytes [ 37, 00, 38, 00, 39, 00, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 29 77A5B115 1 Byte [ 2D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 2B 77A5B117 60 Bytes [ EB, A9, 6A, 57, FF, 15, 4C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 68 77A5B154 30 Bytes [ 00, 00, 8B, 45, 0C, 3B, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegEnumValueU + 87 77A5B173 42 Bytes [ 8B, 45, 18, 83, 20, 00, 33, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + D 77A5C1AB 86 Bytes [ 89, 9D, E4, FE, FF, FF, 29, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 64 77A5C202 8 Bytes [ FF, 01, 0F, 85, D7, 71, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 6D 77A5C20B 30 Bytes [ 85, F0, FE, FF, FF, D1, EF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCloseStore + 8C 77A5C22A 48 Bytes CALL ECA5C22D
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 5 77A5C25B 4 Bytes [ FE, FF, FF, 8D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + A 77A5C260 30 Bytes [ F8, FE, FF, FF, 68, 04, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 29 77A5C27F 26 Bytes [ FF, FF, B5, E0, FE, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 44 77A5C29A 13 Bytes [ 74, 12, FF, B5, E0, FE, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCRLContext + 8A 77A5C2E0 50 Bytes [ 51, AD, 77, FF, 15, CC, 12, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 25 77A5C4DB 79 Bytes [ 68, 18, B5, A5, 77, 53, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 75 77A5C52B 28 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 93 77A5C549 2 Bytes [ CC, 12 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 97 77A5C54D 6 Bytes [ 39, 3D, D4, 50, AD, 77 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetTls + 9E 77A5C554 23 Bytes [ 35, BE, 5B, B8, A5, 77, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 4C 77A5E98A 114 Bytes [ 76, 67, 8B, 45, 08, 8B, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + BF 77A5E9FD 46 Bytes [ 45, 08, 8B, 40, 04, 8B, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + EE 77A5EA2C 6 Bytes [ FF, 75, F8, E8, 0C, E7 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 11D 77A5EA5B 34 Bytes [ 5D, 0C, 85, DB, 56, 57, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindExtension + 151 77A5EA8F 57 Bytes [ 00, 00, 00, 8B, 47, 14, 50, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 23 77A5EB5A 61 Bytes [ 74, 06, 83, 7D, 18, 00, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 61 77A5EB98 20 Bytes [ 80, 00, 00, F7, DE, 1B, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + 76 77A5EBAD 72 Bytes [ 0F, 00, 56, 53, FF, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + BF 77A5EBF6 43 Bytes [ 75, 9D, 8D, 45, 0C, 50, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddStoreToCollection + EB 77A5EC22 23 Bytes [ 50, FF, 15, 4C, 12, A5, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 14 77A5F613 14 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 23 77A5F622 16 Bytes [ 00, 00, 58, 49, A5, 77, BC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 34 77A5F633 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 4E 77A5F64D 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindOIDInfo + 55 77A5F654 30 Bytes [ 00, 00, 00, 00, 1C, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + C 77A5F6F4 54 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 43 77A5F72B 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 49 77A5F731 1 Byte [ 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 4B 77A5F733 4 Bytes [ 00, 00, 00, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateHKCUKeyExU + 50 77A5F738 2 Bytes [ 1C, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 17 77A5FFAC 54 Bytes [ 55, 8B, EC, 8B, 45, 08, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 4E 77A5FFE3 15 Bytes [ 00, 08, 00, 00, 00, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 5F 77A5FFF4 57 Bytes [ 04, 00, 00, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + 99 77A6002E 11 Bytes [ FF, 76, 28, 53, FF, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegQueryValueExU + A5 77A6003A 7 Bytes [ 8B, 46, 28, A9, 00, 00, 04 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 44 77A602C2 1 Byte [ 1C ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 47 77A602C5 1 Byte [ 18 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 4A 77A602C8 1 Byte [ 14 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + 8D 77A6030B 70 Bytes [ 8B, 45, FC, 89, 06, 33, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObjectEx + D4 77A60352 66 Bytes [ 00, FF, 00, 3D, 00, 00, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + E 77A60395 82 Bytes [ 33, C0, EB, F8, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 61 77A603E8 1 Byte [ 36 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 63 77A603EA 52 Bytes [ 3D, E4, 12, A5, 77, 68, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertControlStore + 98 77A6041F 145 Bytes [ 85, C0, 74, 3A, FF, 75, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + 85 77A604B1 24 Bytes [ 76, 08, 53, FF, 75, 14, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + 9E 77A604CA 43 Bytes [ 75, 18, 6A, 40, FF, 15, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + CA 77A604F6 28 Bytes [ 76, 08, 53, FF, 75, 14, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateStore + E7 77A60513 72 Bytes [ 7D, 10, 83, E7, 01, 74, 2D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + 1F 77A6055C 157 Bytes [ 4D, FC, 8B, 45, F0, 3B, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + BD 77A605FA 2 Bytes [ 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashCertificate + C0 77A605FD 155 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 64 77A60699 150 Bytes [ FF, 85, C0, 74, 59, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + FB 77A60730 47 Bytes [ 00, 08, 00, 74, 6F, 81, FE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 12B 77A60760 13 Bytes [ 5C, 00, 4D, 00, 69, 00, 63, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 139 77A6076E 147 Bytes [ 6F, 00, 66, 00, 74, 00, 5C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddSerializedElementToStore + 1CD 77A60802 1 Byte [ 63 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 57 77A608D6 17 Bytes CALL 011DAED3
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 69 77A608E8 34 Bytes [ EE, 8E, A6, 77, 6B, 36, A7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + 8C 77A6090B 21 Bytes [ 77, 63, FC, A8, 77, C5, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + A2 77A60921 5 Bytes [ 75, 18, FF, 76, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenStore + A8 77A60927 55 Bytes [ 15, A0, 12, A5, 77, 8D, 7C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfo + 2 77A6098A 75 Bytes [ 85, C0, 89, 43, 34, 0F, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + 2A 77A609D6 105 Bytes [ A8, 77, 9F, 27, A7, 77, 28, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + 94 77A60A40 62 Bytes [ 85, C0, 0F, 84, AC, 23, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + D3 77A60A7F 23 Bytes [ FF, 85, C0, 0F, 85, 0D, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + EB 77A60A97 7 Bytes [ 85, C0, 0F, 85, B8, 38, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPublicKeyInfoEx + F3 77A60A9F 17 Bytes [ 53, 8D, 45, D0, 50, 68, A4, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 6B 77A60BB0 10 Bytes [ 8B, 75, 14, 8B, 45, 14, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 77 77A60BBC 4 Bytes [ 23, C7, 81, CE ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 7E 77A60BC3 2 Bytes [ 80, 3D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 82 77A60BC7 10 Bytes [ 08, 00, 8D, 5D, EC, 75, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLContextProperty + 8E 77A60BD3 4 Bytes [ 01, 83, 7D, DC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + E 77A60D7F 132 Bytes [ 85, C0, 0F, 84, D9, 02, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + 93 77A60E04 44 Bytes [ FF, 55, 8B, EC, 51, 51, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + C0 77A60E31 8 Bytes [ FF, 83, FA, 12, 0F, 87, 67, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + C9 77A60E3A 32 Bytes [ FF, FF, 24, 95, B2, FD, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Decoder + EA 77A60E5B 18 Bytes CALL 512B1D63
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + B 77A60FCD 24 Bytes [ EB, F5, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 24 77A60FE6 10 Bytes [ 45, FC, 50, 6A, 01, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 2F 77A60FF1 21 Bytes [ 04, 00, 00, 00, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 45 77A61007 7 Bytes [ 14, 8B, 4D, E8, 89, 08, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersignEncoded + 4D 77A6100F 1 Byte [ 10 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + D 77A61250 7 Bytes [ 50, AD, 77, 0D, 04, 80, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 15 77A61258 15 Bytes [ 50, FF, 75, 14, FF, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 25 77A61268 32 Bytes [ 00, 00, 85, C0, 0F, 84, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 46 77A61289 78 Bytes [ FF, 33, DB, 89, 5D, DC, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCertificateChain + 95 77A612D8 36 Bytes [ 39, 5D, DC, 74, 09, 53, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 3D 77A61480 7 Bytes [ 5F, 5E, 5B, 5D, C2, 04, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 49 77A6148C 32 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 6A 77A614AD 43 Bytes [ 55, 8B, EC, FF, 75, 0C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + 96 77A614D9 49 Bytes [ 89, 50, 10, 8B, 11, 85, D2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOIDToAlgId + CA 77A6150D 19 Bytes [ 8B, FF, 55, 8B, EC, 8B, 55, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 6C 77A62AFA 27 Bytes CALL 47681632
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 88 77A62B16 83 Bytes [ 24, 78, 33, F5, D1, C6, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + DC 77A62B6A 26 Bytes JMP 66DA15A2
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + F7 77A62B85 63 Bytes [ AC, 24, 80, 00, 00, 00, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeObject + 137 77A62BC5 31 Bytes [ 00, 33, F5, D1, C6, 89, B4, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareIntegerBlob + 6 77A62D9B 16 Bytes JMP EF23F28B
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareIntegerBlob + 17 77A62DAC 120 Bytes [ 74, 24, 70, 8B, 6C, 24, 78, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + B 77A62E25 70 Bytes JMP 69CA1F35
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 52 77A62E6C 110 Bytes [ F0, 23, EB, 0B, F3, 23, F1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + C1 77A62EDB 79 Bytes [ AC, 24, B4, 00, 00, 00, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 111 77A62F2B 11 Bytes [ 33, F5, D1, C6, 89, B4, 24, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificate + 11D 77A62F37 55 Bytes [ EB, C1, C5, 05, 8D, 84, 28, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCRLContextProperty + 11 77A6363C 75 Bytes [ 8B, AC, 24, F4, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 27 77A63688 42 Bytes [ F5, 8B, AC, 24, 10, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 52 77A636B3 46 Bytes CALL 60DA21EB
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + 81 77A636E2 46 Bytes JMP 8D05C5C1
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + B0 77A63711 27 Bytes [ 33, F5, 8B, AC, 24, 2C, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCompareCertificateName + CC 77A6372D 10 Bytes JMP E833EF33
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 5B 77A6390C 37 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 81 77A63932 88 Bytes [ FB, 08, 57, 89, 45, B0, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + DA 77A6398B 15 Bytes [ FF, 8B, 55, B0, 6A, 05, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + EA 77A6399B 33 Bytes [ 33, C0, B9, 10, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddRefLruEntry + 10C 77A639BD 221 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 15 77A640BA 53 Bytes [ 8D, 45, FC, 50, FF, 75, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 4B 77A640F0 34 Bytes [ 50, 6A, 00, FF, 75, F8, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 6E 77A64113 102 Bytes [ C0, 0F, 84, C3, D1, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + D5 77A6417A 87 Bytes [ 85, C0, 74, 2D, 83, C6, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSyncStore + 12D 77A641D2 19 Bytes [ FF, 8D, 46, 54, 50, E8, 1B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 38 77A64FB0 7 Bytes [ 74, 20, 8B, 5F, 14, 53, E8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 40 77A64FB8 42 Bytes [ 81, FF, FF, 56, 57, E8, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 6C 77A64FE4 24 Bytes [ 6A, 00, FF, 75, 08, E8, 99, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 85 77A64FFD 22 Bytes [ 0F, 85, 99, 47, 01, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInStore + 9C 77A65014 49 Bytes [ 85, C0, 0F, 84, EE, 47, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 6 77A65384 1 Byte [ 45 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 8 77A65386 3 Bytes [ C7, 45, FC ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + D 77A6538B 260 Bytes [ 00, 00, 8B, 55, FC, F6, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 112 77A65490 116 Bytes [ 69, 10, 33, C7, 03, DD, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptReleaseLruEntry + 187 77A65505 43 Bytes [ C6, 03, DA, 33, C2, 23, C3, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 1 77A656C3 31 Bytes [ C7, C1, C6, 0E, 8B, 69, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 21 77A656E3 153 Bytes [ 69, 34, 33, C2, 23, C7, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + BB 77A6577D 318 Bytes [ 22, 61, 9D, 6D, 33, C2, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 1FA 77A658BC 284 Bytes [ 17, 8B, C7, 83, F0, FF, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInsertLruEntry + 317 77A659D9 135 Bytes [ C6, 0F, 8B, C3, 83, F0, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 1A 77A65EFC 97 Bytes [ 33, C0, F3, A6, 8B, 75, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 7C 77A65F5E 14 Bytes [ 58, 18, 8D, 50, 08, EB, E3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 8B 77A65F6D 65 Bytes [ 97, 83, C0, D0, EB, 35, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 154 77A66036 51 Bytes [ 00, EB, ED, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyRevocation + 1E0 77A660C2 84 Bytes [ 5F, 5E, 5B, 5D, C2, 04, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 4B 77A66552 2 Bytes [ 4D, 14 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 4E 77A66555 8 Bytes [ 55, 10, 8B, 75, 0C, 89, 59, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 57 77A6655E 22 Bytes [ 01, 89, 51, 08, 8B, C8, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyTimeValidity + 6E 77A66575 73 Bytes [ 75, 10, 85, F6, 75, 93, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + 32 77A665C9 49 Bytes [ C2, 20, 00, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + A1 77A66638 28 Bytes [ 7C, 0D, F7, 45, 0C, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + C0 77A66657 1 Byte [ 14 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + C2 77A66659 38 Bytes [ 8D, 47, 20, 89, 45, 14, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryData + E9 77A66680 67 Bytes [ 85, C0, 0F, 85, D3, 9A, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + 32 77A66FE6 109 Bytes CALL F5306C76
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + A0 77A67054 16 Bytes [ 18, 04, 0F, 85, 33, 5A, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + B1 77A67065 7 Bytes [ 18, FF, 75, 14, FF, 75, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + BA 77A6706E 4 Bytes [ 0C, FF, 75, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignatureEx + BF 77A67073 122 Bytes [ 55, E0, 8B, F8, 53, FF, 75, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 36 77A672F2 81 Bytes [ 00, 85, C0, 74, 1E, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 88 77A67344 3 Bytes [ 45, 10, 89 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + 8C 77A67348 37 Bytes [ 83, C0, 04, 50, FF, 15, BC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptCreateLruEntry + B2 77A6736E 81 Bytes [ 20, 89, 56, 24, 89, 56, 28, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntry + 35 77A673C0 218 Bytes [ 8B, 45, 1C, C7, 00, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + CB 77A6749B 25 Bytes [ 00, 00, 8B, 46, 0C, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + E5 77A674B5 2 Bytes [ 58, 0C ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + E8 77A674B8 59 Bytes [ 47, 10, 89, 45, F8, 8B, 47, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 125 77A674F5 7 Bytes [ EB, E4, 8B, 45, 18, 83, 20 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnumMatchingLruEntries + 156 77A67526 73 Bytes [ 8D, 47, 20, 50, 53, FF, D6, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 50 77A6779C 99 Bytes [ 85, C0, 89, 45, C8, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + B5 77A67801 2 Bytes [ 11, 86 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + BA 77A67806 89 Bytes [ 43, 04, 8B, 40, 40, 0B, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 114 77A67860 58 Bytes [ 45, A0, 83, C0, 04, 50, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCTLsInStore + 14F 77A6789B 42 Bytes [ FF, 89, 38, 8B, 45, A0, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCRLInStore + 2E 77A6797D 2 Bytes [ 3B, 86 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCRLInStore + 32 77A67981 138 Bytes [ 8D, 5F, 1C, 83, 79, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 1D 77A67A0C 7 Bytes [ 00, 89, 45, C4, E8, 88, D1 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 25 77A67A14 4 Bytes [ FF, 89, 45, C8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 2A 77A67A19 53 Bytes [ 43, 38, 89, 45, CC, 8B, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 60 77A67A4F 18 Bytes [ 55, 08, 0F, 88, DC, 7E, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDDllList + 73 77A67A62 44 Bytes [ 39, 56, 34, BB, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + AC 77A67CE9 3 Bytes [ F7, 86, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + B0 77A67CED 264 Bytes [ 8B, 46, 10, 6A, 05, 59, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 1B9 77A67DF6 100 Bytes [ 33, C0, 40, 5F, 5E, 5B, C9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 21E 77A67E5B 1 Byte [ 5D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetDefaultOIDFunctionAddress + 220 77A67E5D 24 Bytes [ 8B, 43, 04, 8B, 0C, 85, 40, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 13 77A67F03 24 Bytes [ 5D, FF, FF, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 2C 77A67F1C 34 Bytes [ 56, 8B, 75, 08, 57, 33, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 4F 77A67F3F 13 Bytes [ 70, 6C, FF, 70, 68, 68, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 5D 77A67F4D 64 Bytes [ FF, 3B, C7, 74, 1D, 6A, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCertificateInCRL + 9F 77A67F8F 3 Bytes [ 12, 2C, 00 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 27 77A688E1 32 Bytes [ 55, 8B, EC, F6, 45, 14, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 48 77A68902 85 Bytes [ 85, C0, 0F, 85, 7C, 15, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 9E 77A68958 78 Bytes [ 45, 0C, 89, 45, F0, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + ED 77A689A7 80 Bytes [ 55, 8B, EC, 8B, 48, 08, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgClose + 13E 77A689F8 92 Bytes [ 7D, 08, 83, 7F, 18, 00, 6A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + A3 77A693C1 9 Bytes [ 5B, 5F, C9, C2, 10, 00, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + DD 77A693FB 17 Bytes [ 4D, 0C, 8B, 11, 8B, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + EF 77A6940D 25 Bytes [ 09, 50, 04, F6, 41, 05, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + 109 77A69427 25 Bytes [ 5D, C2, 08, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChain + 123 77A69441 3 Bytes [ 5E, 5D, C2 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + 56 77A698B5 22 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + 6D 77A698CC 85 Bytes [ 8D, 46, 1C, 50, FF, 15, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + C4 77A69923 4 Bytes [ 00, 8B, 46, 48 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + C9 77A69928 16 Bytes [ 48, 0C, 85, C9, 74, 07, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertComparePublicKeyInfo + DA 77A69939 33 Bytes [ 48, 10, 85, C9, 74, 07, 6A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCertificateChainPolicy + 34 77A69A80 30 Bytes [ 9A, 64, 01, 00, 8B, 45, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCertificateChainPolicy + 53 77A69A9F 180 Bytes [ 70, 28, 83, C0, 2C, 51, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + 92 77A69B54 34 Bytes [ 0F, 85, 59, 63, 01, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + B5 77A69B77 45 Bytes [ 5F, 1C, 53, 6A, 00, FF, 76, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + E3 77A69BA5 27 Bytes [ FA, FF, FF, 85, C0, 74, 72, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + FF 77A69BC1 19 Bytes [ 00, 85, C0, 74, 58, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashToBeSigned + 113 77A69BD5 38 Bytes [ FF, 8B, 3F, 85, FF, 74, 13, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetSubjectCertificateFromStore + 84 77A6A0BD 84 Bytes [ 0F, 86, D1, 00, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 21 77A6A112 9 Bytes [ FF, 85, C0, 0F, 84, A3, F3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 2B 77A6A11C 113 Bytes [ 75, F8, 8B, 4D, F0, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + 9D 77A6A18E 43 Bytes [ FF, BB, 00, 00, 01, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + C9 77A6A1BA 23 Bytes [ 02, 0B, F2, 8B, 47, 10, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObjectEx + E1 77A6A1D2 40 Bytes [ 06, 81, CE, 80, 00, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 1 77A6A8E5 8 Bytes [ 45, F4, 5F, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + A 77A6A8EE 8 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 13 77A6A8F7 31 Bytes [ EC, 8D, 45, 10, 50, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 33 77A6A917 3 Bytes [ 63, 69, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPGetSignedDataMsg + 3B 77A6A91F 2 Bytes [ D9, 01 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 6E 77A6B018 18 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + BB 77A6B065 47 Bytes [ 0B, 00, 89, 45, FC, E8, 36, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + EB 77A6B095 46 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 11A 77A6B0C4 27 Bytes [ 70, 68, 68, E0, 45, A5, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetParam + 137 77A6B0E1 110 Bytes [ 0F, 84, 59, FD, FE, FF, E9, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + 12 77A6B7DA 135 Bytes [ 33, C0, 8B, FE, AA, 8D, 46, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + 9A 77A6B862 7 Bytes [ EB, F5, 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + A2 77A6B86A 8 Bytes [ FF, 55, 8B, EC, 51, 83, 65, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + AB 77A6B873 81 Bytes [ 53, 56, 8B, 75, 08, 57, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetEnhancedKeyUsage + FD 77A6B8C5 19 Bytes [ 47, 08, 33, C0, 40, 5F, 5E, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 6 77A6C113 65 Bytes [ EF, 11, 81, 7D, 08, B8, 67, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 48 77A6C155 28 Bytes [ 30, 57, 33, FF, 83, FE, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 65 77A6C172 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 67 77A6C174 9 Bytes [ 34, 8B, 75, 0C, 89, 0E, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindAttribute + 71 77A6C17E 2 Bytes [ 70, 04 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 55 77A6C50F 3 Bytes [ 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 59 77A6C513 18 Bytes [ FF, 55, 8B, EC, 83, EC, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 6C 77A6C526 2 Bytes [ 7D, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + DF 77A6C599 60 Bytes [ F0, 3B, F7, 0F, 84, 78, 1E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgControl + 11C 77A6C5D6 38 Bytes [ 4D, 10, 29, 31, 5E, 5D, C2, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 1 77A6D323 6 Bytes [ CF, 8B, D1, C1, E9, 02 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 8 77A6D32A 96 Bytes [ F8, F3, A5, 8B, CA, 83, E1, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + F2 77A6D414 369 Bytes [ 47, 14, 89, 43, 70, E9, DC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 2BF 77A6D5E1 126 Bytes [ 8D, 4D, CC, 51, 68, 98, 69, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetAsn1Encoder + 33E 77A6D660 13 Bytes [ 85, C0, 74, 78, 8B, 4D, F4, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + E 77A6D879 13 Bytes [ FF, 4B, 83, C6, 08, EB, CB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + 1C 77A6D887 177 Bytes [ 55, 8B, EC, 83, EC, 18, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + CE 77A6D939 3 Bytes [ 84, BA, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + D3 77A6D93E 5 Bytes [ 48, 0F, 85, 92, 02 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgUpdate + DA 77A6D945 18 Bytes [ 8B, 46, 48, 3B, C2, 0F, 84, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 14 77A6DE27 116 Bytes [ 00, 8B, 76, 38, 83, C6, 58, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 89 77A6DE9C 10 Bytes [ 89, B5, 60, FF, FF, FF, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 94 77A6DEA7 5 Bytes [ 00, 00, E9, 92, E1 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + F4 77A6DF07 34 Bytes [ 9C, 53, FF, 75, 14, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToDecode + 118 77A6DF2B 57 Bytes [ 89, B5, 68, FF, FF, FF, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 38 77A6DF6F 17 Bytes [ 85, 78, FF, FF, FF, 3B, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 4A 77A6DF81 5 Bytes [ 70, 0C, E8, 19, F0 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 50 77A6DF87 27 Bytes [ FF, 89, 45, E4, 85, C0, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 6C 77A6DFA3 6 Bytes [ 89, 55, E4, E9, CC, E0 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncodedEx + 73 77A6DFAA 52 Bytes [ FF, 48, 75, 15, 8B, B6, 08, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + F 77A6EB1D 79 Bytes [ EC, 83, EC, 18, 53, 56, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 5F 77A6EB6D 5 Bytes [ A1, 00, 00, 00, 85 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 65 77A6EB73 23 Bytes [ 0F, 84, 89, 00, 00, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPLoad + 7D 77A6EB8B 55 Bytes [ 85, C0, 74, 73, 6A, 18, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + F 77A6EBC3 2 Bytes [ 5B, 04 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 12 77A6EBC6 69 Bytes [ DB, 75, 24, 33, F6, 46, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 58 77A6EC0C 7 Bytes [ 00, 90, 90, 90, 90, 90, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 60 77A6EC14 8 Bytes [ 55, 8B, EC, 51, 51, 53, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPVerifyIndirectData + 69 77A6EC1D 219 Bytes [ 35, 54, 50, AD, 77, 33, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 1 77A6ED77 23 Bytes [ 46, 04, 85, C0, 74, 0A, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 1B 77A6ED91 22 Bytes [ 8B, FF, 55, 8B, EC, 5D, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 32 77A6EDA8 51 Bytes [ 75, 08, FF, 36, FF, 76, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 66 77A6EDDC 6 Bytes [ F6, 0F, 84, 83, F1, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptTouchLruEntry + 9F 77A6EE15 19 Bytes [ 55, 8B, EC, 51, 83, 65, FC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + 2 77A6F017 8 Bytes [ FF, 85, C0, 0F, 84, 3D, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + B 77A6F020 139 Bytes [ 8B, 45, FC, F6, 00, 80, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + 97 77A6F0AC 9 Bytes [ 4D, E4, 3B, 4D, D8, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + A1 77A6F0B6 28 Bytes CALL AB7B6646
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptSetTls + BE 77A6F0D3 45 Bytes [ 75, 08, FF, 75, 0C, E8, 0F, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 31 77A6FC50 95 Bytes [ B3, FE, FF, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 91 77A6FCB0 56 Bytes [ C6, 45, F7, C0, C6, 45, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 103 77A6FD22 13 Bytes [ FF, 15, 08, 12, A5, 77, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 111 77A6FD30 11 Bytes [ FF, 56, FF, 15, 4C, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCertificatesInStore + 11D 77A6FD3C 15 Bytes [ FF, FF, 75, 10, FF, 75, 0C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 31 77A707AD 18 Bytes [ 83, C6, 04, 56, 68, 01, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 44 77A707C0 6 Bytes [ 83, C6, 04, 56, 68, 02 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 4B 77A707C7 5 Bytes [ 00, 80, E9, D0, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 52 77A707CE 37 Bytes [ 66, C7, 06, 04, 00, 83, C6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCertificateChainEngine + 78 77A707F4 197 Bytes [ 80, EB, E5, 66, C7, 06, 08, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 77 77A70C9F 212 Bytes [ 90, 90, 90, 90, 90, A1, 7C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 14C 77A70D74 44 Bytes [ 75, 0C, FF, D7, 83, 7D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 179 77A70DA1 34 Bytes [ 75, 0C, FF, D7, 83, 7D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 19C 77A70DC4 35 Bytes [ 75, 0C, FF, D7, 8B, 35, 5C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLsInStore + 1C0 77A70DE8 27 Bytes [ 15, 6C, 14, A5, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveStoreFromCollection + 10 77A70E04 18 Bytes [ 75, F4, FF, 75, F8, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveStoreFromCollection + 23 77A70E17 42 Bytes [ 0C, FF, 75, 08, FF, D6, F7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertUpdateStore 77A70E44 142 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertUpdateStore + B5 77A70EF9 80 Bytes [ FF, 5F, 5E, 5D, C2, 20, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 22 77A70F4A 21 Bytes [ 8D, 45, FC, 50, 8D, 45, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 38 77A70F60 73 Bytes [ F6, 06, 20, 74, 1A, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptRemoveLruEntry + 82 77A70FAA 138 Bytes [ 0A, 5B, C9, C2, 14, 00, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 98 77A71088 49 Bytes [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + CA 77A710BA 28 Bytes [ 01, 00, FF, 75, 08, E8, B4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + E7 77A710D7 27 Bytes [ 89, 01, 47, 39, 5D, E0, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 103 77A710F3 10 Bytes [ 55, 8B, EC, 6A, 00, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptQueryObject + 10F 77A710FF 98 Bytes [ 00, 5D, C2, 04, 00, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 21 77A712AB 37 Bytes [ 0F, 84, B3, C7, 00, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 47 77A712D1 18 Bytes [ C2, 08, 00, 83, 66, 04, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 76 77A71300 11 Bytes [ FF, 81, 7D, 08, FF, FF, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 82 77A7130C 20 Bytes [ 08, 68, B8, 45, A5, 77, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCRLToStore + 97 77A71321 22 Bytes [ FF, 75, 18, C7, 45, FC, 01, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 2 77A72097 98 Bytes [ 75, 14, FF, 75, 10, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 6F 77A72104 2 Bytes [ 64, C9 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 73 77A72108 2 Bytes [ 77, C9 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + 77 77A7210C 105 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegDeleteValueU + E1 77A72176 4 Bytes [ 45, 2C, 3B, C7 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc 77A72424 19 Bytes [ 43, 72, 79, 70, 74, 44, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + 88 77A724AC 111 Bytes [ C6, 45, F9, 05, 88, 5D, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + F9 77A7251D 5 Bytes [ 01, 8D, 45, EC, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + FF 77A72523 39 Bytes [ D6, 85, C0, 74, 0D, C7, 05, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemAlloc + 127 77A7254B 61 Bytes [ FF, 55, 8B, EC, 56, 8B, F0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 120 77A729FF 9 Bytes [ FF, 85, C0, 74, 1F, FF, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 12A 77A72A09 2 Bytes [ 75, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 131 77A72A10 1 Byte [ 08 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 133 77A72A12 122 Bytes [ 15, 5C, 14, A5, 77, F7, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSerializeCRLStoreElement + 1AE 77A72A8D 30 Bytes [ 55, 18, 57, 6A, 05, 59, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + 99 77A73033 8 Bytes [ 00, 63, 00, 72, 00, 6F, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + A2 77A7303C 19 Bytes [ 6F, 00, 66, 00, 74, 00, 5C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + B6 77A73050 22 Bytes [ 43, 00, 65, 00, 72, 00, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + CD 77A73067 44 Bytes [ 00, 5C, 00, 4D, 00, 79, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegSetValueExU + FA 77A73094 27 Bytes [ 90, 8B, FF, 55, 8B, EC, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + A 77A7320F 6 Bytes [ 85, C0, 0F, 85, 21, 80 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 11 77A73216 15 Bytes [ 00, C3, 33, DB, 43, E9, AF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 22 77A73227 7 Bytes [ 80, 4D, E5, 04, E9, 9A, BA ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 2B 77A73230 19 Bytes [ C7, 06, 03, 00, 00, 00, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetFileVersion + 3F 77A73244 17 Bytes [ 15, 08, 12, A5, 77, E9, 87, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 27 77A73EE1 34 Bytes [ C6, 5E, 5D, C2, 18, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 4A 77A73F04 3 Bytes [ 87, 33, 74 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + 4F 77A73F09 93 Bytes [ 56, FF, 75, 0C, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + AD 77A73F67 62 Bytes [ 00, FF, 75, 18, FF, 75, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptProtectData + EC 77A73FA6 66 Bytes [ 0F, 84, 10, 50, 00, 00, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + E 77A740AF 199 Bytes [ 90, 45, 6E, 74, 65, 72, 43, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + D9 77A7417A 5 Bytes [ C0, 74, 5A, B8, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + DF 77A74180 44 Bytes [ 05, 00, 39, 45, FC, 77, 0B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + 10C 77A741AD 54 Bytes [ 15, 04, 12, A5, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnprotectData + 144 77A741E5 10 Bytes [ 90, 90, 90, 75, 00, 73, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 23 77A74523 27 Bytes [ 8D, 8D, AC, FD, FF, FF, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 3F 77A7453F 9 Bytes [ F7, 85, AC, FD, FF, FF, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeLruCache + 49 77A74549 105 Bytes [ 0F, 84, 4A, 7C, 00, 00, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemFree + 2 77A745B3 14 Bytes [ C9, C2, 14, 00, 85, DB, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUninstallAsn1Module 77A745C2 75 Bytes [ 90, 90, 2A, 00, 00, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 35 77A7460F 5 Bytes [ 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 91 77A7466B 12 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 9E 77A74678 69 Bytes [ 56, 8B, 75, 08, F6, 46, 2A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + E7 77A746C1 29 Bytes [ 90, 8B, FF, 55, 8B, EC, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFreeTls + 105 77A746DF 37 Bytes [ 00, BB, 00, 00, 00, 80, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CloseCertPerformanceData + 3A 77A81CFE 84 Bytes [ 25, CC, 11, A5, 77, FF, 40, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 4 77A81D53 18 Bytes [ 18, 0F, B7, D2, C1, E3, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 17 77A81D66 3 Bytes [ CA, AA, FD ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 1B 77A81D6A 6 Bytes [ 33, C0, E9, 66, 93, FD ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + 22 77A81D71 148 Bytes [ 90, 90, 90, 63, 72, 79, 70, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CreateFileU + B7 77A81E06 66 Bytes [ 00, 00, 2D, 2D, 2D, 2D, 2D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 2F 77A8242C 33 Bytes [ 61, 00, 6C, 00, 43, 00, 6F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 51 77A8244E 77 Bytes [ 6F, 00, 6E, 00, 00, 00, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireContextU + 9F 77A8249C 46 Bytes [ 54, 00, 69, 00, 74, 00, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 2B 77A824CC 1 Byte [ 45 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 2D 77A824CE 25 Bytes [ 6D, 00, 61, 00, 69, 00, 6C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 47 77A824E8 79 Bytes [ 4C, 00, 00, 00, 43, 00, 4E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignHashU + 97 77A82538 70 Bytes [ 48, 00, 41, 00, 31, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + 43 77A82580 39 Bytes [ 31, 2E, 33, 2E, 31, 34, 2E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + 6B 77A825A8 69 Bytes [ 53, 00, 41, 00, 00, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifySignatureU + B3 77A825F0 30 Bytes [ 31, 2E, 33, 2E, 31, 34, 2E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 1F 77A82610 59 Bytes [ 73, 00, 68, 00, 61, 00, 52, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 5B 77A8264C 1 Byte [ 53 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 5D 77A8264E 106 Bytes [ 41, 00, 00, 00, 90, 90, 31, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + C8 77A826B9 78 Bytes [ 00, 53, 00, 44, 00, 48, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetProviderU + 117 77A82708 1 Byte [ 53 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumProvidersU + 83 77A82884 279 Bytes [ 6F, 73, 73, 53, 65, 74, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 1E 77A8299C 170 Bytes [ 31, 2E, 32, 2E, 38, 34, 30, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + C9 77A82A47 100 Bytes [ 00, 06, 00, 00, 00, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 12F 77A82AAD 29 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 14D 77A82ACB 41 Bytes [ 55, 8B, EC, 8B, 0D, 24, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!RegCreateKeyExU + 177 77A82AF5 35 Bytes [ EB, 2E, A1, 44, 73, AD, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 7C 77A83565 34 Bytes [ 08, FF, 15, E4, 52, AD, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 9F 77A83588 17 Bytes [ EC, 81, EC, 0C, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + B1 77A8359A 3 Bytes [ 08, 8D, 8D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + B5 77A8359E 83 Bytes [ FE, FF, FF, 51, 50, 68, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringA + 163 77A8364C 14 Bytes [ 02, 00, 56, 57, 68, 98, 27, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 12 77A83819 2 Bytes [ FF, E0 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 15 77A8381C 3 Bytes JMP 77A83611 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 19 77A83820 135 Bytes [ FF, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + A1 77A838A8 111 Bytes [ 8D, DC, FD, FF, FF, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptBinaryToStringW + 111 77A83918 3 Bytes [ B5, DC, FD ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + A8 77A83A9B 4 Bytes [ FF, 8B, CB, 51 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + AE 77A83AA1 21 Bytes [ 0C, 89, 45, FC, 8B, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + C4 77A83AB7 3 Bytes [ A5, 77, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + C8 77A83ABB 17 Bytes [ 85, C8, FD, FF, FF, 89, B5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryA + DA 77A83ACD 25 Bytes [ D7, 85, C0, 74, 09, 83, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 2 77A83AE7 12 Bytes [ FF, FF, 85, F0, FD, FF, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + F 77A83AF4 53 Bytes [ 77, 08, 39, B5, F0, FD, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 45 77A83B2A 39 Bytes [ 15, 5C, 12, A5, 77, 6A, 0E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 6D 77A83B52 30 Bytes [ 53, FF, 75, 0C, FF, B5, C8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptStringToBinaryW + 8C 77A83B71 22 Bytes [ FF, 75, 34, 8B, BD, CC, FD, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4 77A86C12 70 Bytes [ 45, 18, 68, 15, 00, 09, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4B 77A86C59 2 Bytes [ FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + 4E 77A86C5C 167 Bytes [ EC, 8B, 45, 10, 8B, 00, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInSortedCTL + F6 77A86D04 50 Bytes [ FF, 1F, 00, 00, FD, 3F, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 2E 77A86D37 257 Bytes [ EB, 1E, 33, C0, 85, D2, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 131 77A86E3A 10 Bytes [ 40, EB, 22, 6A, 0D, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 13C 77A86E45 37 Bytes [ 8B, 45, 0C, 83, 20, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 162 77A86E6B 42 Bytes [ 00, 58, 0E, A8, 77, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSubjectInSortedCTL + 18D 77A86E96 108 Bytes [ FF, 55, 8B, EC, 81, EC, 88, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + B 77A86FFE 8 Bytes [ 18, 68, E0, 61, A8, 77, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + 14 77A87007 100 Bytes [ 15, E4, 12, A5, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + 7A 77A8706D 113 Bytes [ 8B, 4D, D0, 89, 08, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + EC 77A870DF 5 Bytes [ F4, E8, 48, 72, FD ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumCRLContextProperties + F2 77A870E5 76 Bytes [ 85, C0, 7E, 29, 8B, 45, B8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 6C 77A872DA 43 Bytes [ DC, 03, D8, 89, 5D, C4, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 98 77A87306 2 Bytes [ EC, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 9B 77A87309 1 Byte [ 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetStoreProperty + 9D 77A8730B 294 Bytes [ 89, 45, C0, 33, C0, 40, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 9C 77A87433 43 Bytes [ 50, 8D, 45, CC, 50, 56, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + C8 77A8745F 63 Bytes [ 45, CC, 2B, F0, 89, 75, 88, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 108 77A8749F 63 Bytes JMP 77A87693 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 148 77A874DF 40 Bytes [ 66, A8, 77, 8D, 45, DC, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindSubjectInCTL + 171 77A87508 41 Bytes [ 4D, E0, 85, C0, 0F, 84, FE, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 13 77A87856 17 Bytes [ D8, 89, 5D, AC, 85, DB, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 25 77A87868 35 Bytes [ FF, 47, 89, 3B, C7, 43, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 49 77A8788C 43 Bytes [ B5, 70, FF, FF, FF, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 75 77A878B8 39 Bytes [ 4B, 50, 89, 4D, CC, 89, 79, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLEntryFromCertificateContextProperties + 9D 77A878E0 109 Bytes [ 50, FF, 75, D4, FF, 75, 98, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDeleteCRLFromStore + 2 77A88142 221 Bytes [ 15, 4C, 12, A5, 77, 83, 7D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 7D 77A88231 31 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 9D 77A88251 35 Bytes CALL 77A8816D C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + C1 77A88275 41 Bytes [ 7D, 0C, 0E, 56, 57, 0F, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + EC 77A882A0 26 Bytes [ 83, 3F, 03, 75, 78, 57, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindCTLInStore + 107 77A882BB 24 Bytes [ 15, BC, 12, A5, 77, 57, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + E 77A88487 23 Bytes [ 8B, F0, 85, F6, 74, 2D, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 26 77A8849F 112 Bytes [ C0, 04, 49, 75, F5, 68, 4B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 97 77A88510 6 Bytes [ 5D, 0C, 56, 8B, 75, 08 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + 9E 77A88517 73 Bytes [ 46, 0C, 57, 33, FF, F6, C3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateContext + E8 77A88561 198 Bytes [ 70, 0C, 6A, 24, FF, 36, E8, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSaveStore + 2B 77A88969 180 Bytes [ 8B, 45, A8, 83, 38, 14, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToStore + 4 77A88A1E 55 Bytes [ C8, 83, E1, 03, F3, A4, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToStore + 3C 77A88A56 62 Bytes [ 7D, B4, 00, 0F, 85, A6, 01, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddCRLContextToStore + 6 77A88A95 8 Bytes [ 50, 57, 56, 89, 45, BC, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddCRLContextToStore + 2A 77A88AB9 51 Bytes [ 85, C0, 89, 45, C0, 0F, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetCRLFromStore + 2 77A88AED 64 Bytes [ FF, 75, C0, 8B, F8, E8, B9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCTLToStore + 38 77A88BF6 64 Bytes [ C0, 89, 45, D4, 0F, 85, 69, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 2B 77A88C37 41 Bytes [ 45, D0, 29, 45, B0, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 55 77A88C61 333 Bytes [ 55, 8B, EC, 83, EC, 14, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1A3 77A88DAF 18 Bytes [ 07, 80, FF, 15, 4C, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1B6 77A88DC2 20 Bytes [ 83, FF, 04, 8B, 75, 0C, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateCTLContext + 1CB 77A88DD7 4 Bytes [ FF, 6A, 00, 6A ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 33 77A892AA 73 Bytes [ 00, 68, 05, 20, 09, 80, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 7D 77A892F4 6 Bytes [ FF, 75, 14, 89, 75, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetKeyIdentifierProperty + 84 77A892FB 48 Bytes [ 75, 10, 53, FF, 76, 14, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 34 77A8933D 69 Bytes [ 45, 14, 33, F6, 3B, C6, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 7A 77A89383 35 Bytes [ DB, 89, 5D, E0, 89, 5D, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + 9E 77A893A7 33 Bytes [ 09, 83, 4D, FC, FF, E9, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + C0 77A893C9 34 Bytes [ 0C, 8B, 4E, 04, 53, 52, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSetKeyIdentifierProperty + E3 77A893EC 59 Bytes [ BB, FD, FF, 85, C0, 74, B5, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + 2 77A895AF 55 Bytes [ 89, 45, E4, 39, 7D, E4, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + 3A 77A895E7 61 Bytes [ 15, 4C, 12, A5, 77, 8B, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + C9 77A89676 12 Bytes [ 8B, 7E, 14, EB, 0C, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + D6 77A89683 3 Bytes [ D3, 81, FD ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumKeyIdentifierProperties + DA 77A89687 15 Bytes [ 85, FF, 75, F0, FF, 75, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 2 77A8994A 29 Bytes [ 3B, CF, 0F, 86, B0, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 20 77A89968 28 Bytes [ 00, 00, 00, 6A, 02, 57, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 3D 77A89985 91 Bytes [ 00, 00, FF, 75, 1C, 56, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + 99 77A899E1 56 Bytes [ 75, 18, 51, FF, 75, 0C, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifySubjectCertificateContext + D2 77A89A1A 29 Bytes [ 8B, FF, 55, 8B, EC, 51, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 1A 77A89A38 59 Bytes [ 75, 14, FF, 75, 10, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 56 77A89A74 80 Bytes [ 75, 10, FF, 75, 0C, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + A7 77A89AC5 113 Bytes CALL 77A89374 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 11B 77A89B39 1 Byte [ 89 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptAcquireCertificatePrivateKey + 11D 77A89B3B 76 Bytes [ F0, 89, 75, F4, 74, 07, C7, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 1C 77A89C5D 95 Bytes [ 6A, 00, 6A, FF, 6A, 04, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 7C 77A89CBD 125 Bytes [ F8, 68, 8D, 06, A6, 77, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + FA 77A89D3B 2 Bytes [ 46, 24 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + FD 77A89D3E 25 Bytes [ 7E, 1C, 53, 89, 45, 0C, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetCertificateContextPropertiesFromCTLEntry + 117 77A89D58 71 Bytes [ 15, 08, 12, A5, 77, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreA 77A89E0A 42 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreA + 2B 77A89E35 69 Bytes [ 74, 37, 84, E4, 79, 10, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertOpenSystemStoreW + 32 77A89E7B 25 Bytes [ 75, 04, 33, FF, EB, 4F, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 8 77A89E95 8 Bytes [ 8B, F8, 85, FF, 75, 0D, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 11 77A89E9E 24 Bytes [ D6, 85, C0, 75, 01, 47, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 2A 77A89EB7 3 Bytes [ 75, 1C, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreA + 2E 77A89EBB 69 Bytes [ FC, FF, 75, F8, 53, E8, 2B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 2A 77A89F01 43 Bytes [ 89, 7D, F8, 89, 7D, F4, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 56 77A89F2D 3 Bytes [ 00, 01, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 5A 77A89F31 91 Bytes [ 03, 09, 45, 0C, 8B, 4D, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + B6 77A89F8D 82 Bytes [ 83, F8, FF, 89, 45, FC, 0F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEncodedCertificateToSystemStoreW + 109 77A89FE0 109 Bytes CALL 77A869EE C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 4B 77A8A3A6 40 Bytes [ 75, 0C, FF, 77, 08, E8, 34, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 74 77A8A3CF 3 Bytes [ 9D, DD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + 7A 77A8A3D5 2 Bytes [ 74, 32 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + A2 77A8A3FD 58 Bytes CALL 77A90535 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertSetEnhancedKeyUsage + DD 77A8A438 86 Bytes [ 75, 10, 33, FF, FF, 75, 0C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + 4 77A8A52F 98 Bytes [ 45, 10, 83, C7, 04, 3B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + 67 77A8A592 96 Bytes [ 1A, AB, FC, FF, FF, 75, F0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + C8 77A8A5F3 22 Bytes [ F0, 85, F6, 74, 14, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + DF 77A8A60A 9 Bytes [ 8B, F0, FF, 75, 0C, E8, 9C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetValidUsages + E9 77A8A614 76 Bytes [ EB, 14, 68, 2C, 94, A8, 77, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 4 77A8A872 16 Bytes [ 51, 14, 3B, 57, 10, 74, 11, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 15 77A8A883 80 Bytes CALL 77A8A707 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + 66 77A8A8D4 121 Bytes [ 68, 07, 20, 09, 80, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertAddEnhancedKeyUsageIdentifier + E0 77A8A94E 127 Bytes [ 4D, 10, 8B, 01, A9, F8, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 61 77A8A9CE 9 Bytes [ E4, 50, 56, 56, 68, 00, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 6B 77A8A9D8 8 Bytes [ 02, 8D, 45, D4, 50, E8, 95, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 74 77A8A9E1 60 Bytes [ FF, 85, C0, 74, 05, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + B1 77A8AA1E 96 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRemoveEnhancedKeyUsageIdentifier + 113 77A8AA80 68 Bytes [ 85, C0, 74, 17, 8B, 45, 1C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProvForEncrypt + 2B 77A8ABE5 32 Bytes [ 75, E4, 8B, F0, FF, 15, 88, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetDefaultCryptProvForEncrypt + 11B 77A8ACD5 82 Bytes [ 83, 7E, 04, 01, 0F, 85, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 4F 77A8AD3B 2 Bytes [ 4D, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 52 77A8AD3E 37 Bytes [ 75, E4, 8B, C1, C1, E9, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 78 77A8AD64 10 Bytes [ 53, EB, 27, FF, 75, EC, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + 83 77A8AD6F 38 Bytes [ 8B, F8, 3B, FE, 74, 7E, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertIsRDNAttrsInCertificateName + AA 77A8AD96 26 Bytes [ 8B, 75, FC, EB, 33, E8, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 12 77A8AE94 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 14 77A8AE96 40 Bytes CALL 77A8AE07 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 3D 77A8AEBF 4 Bytes [ F6, 74, 08, 6A ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 7C 77A8AEFE 3 Bytes [ 18, EB, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignCertificate + 80 77A8AF02 45 Bytes [ 85, C0, 75, 02, 33, DB, 85, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 4 77A8B050 18 Bytes [ 36, 8B, C8, 8B, D1, C1, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 17 77A8B063 2 Bytes [ A4, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 1A 77A8B066 10 Bytes [ 10, 8B, 75, EC, 83, C6, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 25 77A8B071 7 Bytes CALL ED9525FF
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncodeCertificate + 2D 77A8B079 29 Bytes [ 4D, F4, 29, 4D, FC, 85, C9, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 21 77A8B293 29 Bytes [ 55, 8B, EC, 56, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 3F 77A8B2B1 72 Bytes [ 07, 80, FF, 15, 4C, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + 88 77A8B2FA 60 Bytes [ 39, 3B, 89, 4D, F8, 76, 1B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + D3 77A8B345 23 Bytes [ 4D, FC, 41, 3B, 4D, F4, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindRDNAttr + EB 77A8B35D 20 Bytes [ 55, 8B, EC, 51, 51, 83, 7D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 30 77A8B3C0 18 Bytes [ EC, 51, 8D, 45, FC, 50, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 43 77A8B3D3 26 Bytes [ 85, C0, 75, 08, FF, 15, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 5E 77A8B3EE 35 Bytes [ 07, B8, 0E, 00, 07, 80, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 82 77A8B412 1 Byte [ 15 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashPublicKeyInfo + 84 77A8B414 8 Bytes [ 12, A5, 77, EB, 13, 8B, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfoEx + 5 77A8BE87 54 Bytes [ 83, EC, 44, A1, 00, 51, AD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfoEx + 3C 77A8BEBE 58 Bytes [ 85, C0, 0F, 84, BB, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfo + 2 77A8BEF9 8 Bytes [ 36, FF, 75, D0, E8, 90, 60, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPublicKeyInfo + B 77A8BF02 39 Bytes JMP 77A8BFE7 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + D 77A8BF2B 1 Byte [ CC ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + F 77A8BF2D 8 Bytes [ 53, 53, FF, 75, C0, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + 18 77A8BF36 56 Bytes [ 15, A0, 10, A5, 77, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateKeyIdentifierFromCSP + 52 77A8BF70 184 Bytes [ 0C, 89, 7D, C8, FF, 75, CC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 66 77A8C029 50 Bytes [ 15, F7, 45, FC, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 99 77A8C05C 62 Bytes [ 59, 33, C0, 8D, 7D, E0, F3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + D8 77A8C09B 51 Bytes [ 75, 0C, FF, 75, 08, E8, DD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 10C 77A8C0CF 12 Bytes [ E4, 57, FF, 75, 0C, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptInstallDefaultContext + 119 77A8C0DC 113 Bytes [ 85, C0, 75, 09, 8B, 45, 28, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 27 77A8C14E 13 Bytes [ 8D, 45, F8, 50, 8D, 45, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 35 77A8C15C 147 Bytes [ 8D, 5D, F8, 8B, 75, 0C, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + C9 77A8C1F0 135 Bytes [ 39, 7D, 10, 76, 3C, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 151 77A8C278 8 Bytes [ 45, 0C, 8B, 08, 85, C9, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUninstallDefaultContext + 15A 77A8C281 10 Bytes [ 70, 04, 57, 89, 4D, 0C, 76, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 2E 77A8C530 12 Bytes [ 75, 08, FF, D6, 85, C0, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 3B 77A8C53D 128 Bytes [ 1E, 00, 00, 21, 7D, F4, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + BD 77A8C5BF 57 Bytes [ 08, FF, 15, 84, 12, A5, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + F7 77A8C5F9 238 Bytes [ 08, 8B, F8, 8B, C1, C1, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindCertificateKeyProvInfo + 1E6 77A8C6E8 59 Bytes [ 3B, C6, 75, 0D, 6A, 02, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyCertificateSignature + 25 77A8C724 32 Bytes [ 8D, 45, F0, 50, 8D, 45, F4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + 10 77A8C745 7 Bytes [ 55, 10, 56, FF, 75, E8, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + C5 77A8C7FA 36 Bytes [ 30, 5E, 8B, C3, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + EA 77A8C81F 18 Bytes [ 75, 10, 89, 01, 8B, 4D, 2C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + FD 77A8C832 23 Bytes [ 5D, C2, 28, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetPublicKeyLength + 115 77A8C84A 7 Bytes [ 28, 33, DB, 57, 8B, 7D, 20 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 4A 77A8C8D7 54 Bytes [ 8B, 45, 2C, 89, 1E, 89, 1F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 82 77A8C90F 1 Byte [ FC ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 85 77A8C912 18 Bytes [ F4, 0F, 84, E0, 01, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + 98 77A8C925 60 Bytes [ 50, 51, 6A, 27, FF, 75, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertCreateSelfSignCertificate + D5 77A8C962 61 Bytes [ 08, 0F, 84, 89, 01, 00, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 35 77A8DE94 1 Byte [ F6 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 37 77A8DE96 62 Bytes [ 07, 08, 04, 11, 33, F6, 41, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterSystemStore + 76 77A8DED5 94 Bytes [ FF, EB, 08, FF, 75, 0C, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 3E 77A8DF34 36 Bytes [ 10, 50, 6A, 04, 6A, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 63 77A8DF59 15 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 74 77A8DF6A 1 Byte [ 08 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + 76 77A8DF6C 94 Bytes [ 8D, 45, 0C, 50, 6A, 00, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRegisterPhysicalStore + D5 77A8DFCB 30 Bytes [ 57, 8D, 45, F8, 50, 57, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A 77A8E0D3 142 Bytes [ C7, 5F, 5E, 5B, C9, C2, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + 99 77A8E162 2 Bytes [ F4, 57 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + 9C 77A8E165 2 Bytes [ 47, 6F ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A0 77A8E169 3 Bytes [ FF, 75, F8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterSystemStore + A4 77A8E16D 21 Bytes [ 15, 10, 10, A5, 77, 39, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 27 77A8E204 101 Bytes [ FF, 8B, D8, 83, FB, FF, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + AC 77A8E289 7 Bytes [ 90, 90, 90, 90, 8B, FF, 55 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + B4 77A8E291 159 Bytes [ EC, 83, EC, 5C, A1, 00, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 16C 77A8E349 66 Bytes [ 57, 6A, 04, 53, 53, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertUnregisterPhysicalStore + 1AF 77A8E38C 7 Bytes [ 53, 68, 2C, BA, A5, 77, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 45 77A8E512 21 Bytes [ 8B, F0, 8B, 45, C0, 56, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 5B 77A8E528 3 Bytes [ 6E, 5A, FE ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 5F 77A8E52C 5 Bytes [ 85, C0, 0F, 85, 98 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + 66 77A8E533 80 Bytes [ 00, FF, 75, CC, 03, DE, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumSystemStore + B7 77A8E584 23 Bytes [ 33, F6, 39, 75, D0, 76, 20, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 64 77A8EB99 1 Byte [ 55 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 66 77A8EB9B 44 Bytes [ EC, 8B, 45, 08, 56, 33, F6, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 93 77A8EBC8 89 Bytes [ C6, 5E, 5D, C2, 04, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + ED 77A8EC22 20 Bytes [ 5E, 5F, 5D, C2, 0C, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertEnumPhysicalStore + 102 77A8EC37 63 Bytes [ F6, 74, 17, 8B, 45, 0C, 83, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 1 77A905C1 27 Bytes [ F0, 85, F6, 74, 31, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 2A 77A905EA 82 Bytes [ EB, 0D, 68, 57, 00, 07, 80, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 113 77A906D3 12 Bytes [ 90, 90, 8B, FF, 55, 8B, EC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 120 77A906E0 33 Bytes [ AD, 77, 56, 8B, 75, 14, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFindChainInStore + 142 77A90702 10 Bytes [ E4, FF, 75, 10, 89, 45, DC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 10 77A90852 110 Bytes [ 98, 8B, 45, 8C, FF, 75, A4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 7F 77A908C1 112 Bytes [ 33, C0, 5E, 40, 5B, E8, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + F0 77A90932 7 Bytes [ A6, 77, 57, E8, C2, DD, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + F8 77A9093A 13 Bytes [ 85, 5E, 28, 89, 45, 10, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrW + 106 77A90948 167 Bytes [ A1, 64, 54, AD, 77, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 11 77A9190E 2 Bytes [ 24, 00 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 14 77A91911 58 Bytes [ 66, 89, 11, 03, CF, FF, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 4F 77A9194C 22 Bytes [ 4D, 0C, 8B, 01, 8B, 49, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 66 77A91963 33 Bytes CALL 8F1FF4ED
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrW + 88 77A91985 96 Bytes [ 74, 08, 8B, 4D, 10, 66, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + 5B 77A919E9 91 Bytes [ 90, 8B, FF, 55, 8B, EC, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + B7 77A91A45 7 Bytes [ 20, 51, B9, 84, 0A, A9, 77 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + BF 77A91A4D 3 Bytes [ 48, FF, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + C3 77A91A51 60 Bytes [ 85, C0, 75, 11, B8, 21, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertNameToStrA + 100 77A91A8E 19 Bytes [ 2D, 00, 2E, 00, 2F, 00, 3A, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + A 77A91CB9 18 Bytes [ 83, FF, 0B, 0F, 84, 80, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 1E 77A91CCD 44 Bytes [ 85, DB, 74, 32, FF, 75, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 4B 77A91CFA 8 Bytes [ 01, 8B, 4D, FC, 66, 83, 24, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + 54 77A91D03 89 Bytes [ 8B, 4D, FC, 33, C0, 01, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameW + AE 77A91D5D 2 Bytes [ FF, 10 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 2 77A921FF 54 Bytes [ FF, 5F, 5E, C9, C2, 10, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 39 77A92236 24 Bytes [ 04, FD, 07, 00, 00, 00, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 52 77A9224F 20 Bytes [ 3E, 89, 55, 14, EB, 73, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + 67 77A92264 62 Bytes [ 45, F8, 8B, C6, C1, E0, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertStrToNameA + A6 77A922A3 35 Bytes CALL 77A92181 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 68 77A92671 75 Bytes [ 75, F0, 8D, 45, F4, 53, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + B4 77A926BD 86 Bytes [ 79, 04, 89, 10, 89, 70, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 10C 77A92715 53 Bytes [ 00, 20, C7, 45, EC, F4, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 142 77A9274B 64 Bytes CALL 77A9269A C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringW + 183 77A9278C 1 Byte [ 50 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 4 77A928D5 60 Bytes [ 45, FC, 5E, 40, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 41 77A92912 20 Bytes [ 71, 04, C1, E0, 08, 6A, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertGetNameStringA + 56 77A92927 68 Bytes [ F0, FF, 75, 14, FF, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 3A 77A9296C 95 Bytes [ 15, A8, 12, A5, 77, 83, F8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 9A 77A929CC 1 Byte [ 75 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 9C 77A929CE 106 Bytes CALL 77A92947 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 107 77A92A39 27 Bytes [ 85, C0, 5F, 74, 08, 8B, 40, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertRDNValueToStrA + 123 77A92A55 5 Bytes [ 90, 90, 90, 90, 90 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 1 77A92C14 7 Bytes [ FA, EB, 50, 83, 7D, FC, 01 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 9 77A92C1C 4 Bytes [ 2E, 66, 3B, D8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + E 77A92C21 18 Bytes [ 7A, 66, 83, FB, 22, 75, 3F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 21 77A92C34 5 Bytes [ D0, EB, 30, 8B, 4D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertVerifyCTLUsage + 27 77A92C3A 89 Bytes [ 8B, C2, 2B, C7, D1, F8, 89, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 2 77A93730 68 Bytes [ 85, C0, 89, 45, F0, 75, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 47 77A93775 24 Bytes CALL 77A93316 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 60 77A9378E 52 Bytes [ 89, 45, F4, 8D, 45, FC, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 95 77A937C3 3 Bytes JMP 03A933E4
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptCreateAsyncHandle + 99 77A937C7 71 Bytes [ 8B, F0, 85, F6, 74, 2C, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetAsyncParam + 12 77A938F4 3 Bytes [ DF, 1B, FC ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetAsyncParam + 16 77A938F8 112 Bytes [ 8B, F8, 85, FF, 74, 13, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetMessageSignerCount + 25 77A9396B 112 Bytes CALL 77A9183F C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage 77A939E0 42 Bytes [ 85, F6, 74, 29, 8B, 0A, B8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 2C 77A93A0C 19 Bytes [ 32, C3, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 40 77A93A20 38 Bytes [ 7D, 20, C7, 45, D8, 27, 20, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + 67 77A93A47 91 Bytes [ FF, 75, 08, FF, 55, DC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptHashMessage + D0 77A93AB0 17 Bytes [ C4, 89, 45, E0, 83, 4D, FC, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncryptMessage + 2E 77A942D9 9 Bytes [ 45, 10, 50, 57, 53, 89, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncryptMessage + 38 77A942E3 81 Bytes [ 62, FD, FF, 85, C0, 0F, 84, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageHash + 1 77A94335 2 Bytes [ 47, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageHash + 4 77A94338 56 Bytes [ 38, 83, 7F, 0C, 02, 72, 66, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageHash + 10 77A94371 25 Bytes [ 00, 8B, 40, 04, 6A, 03, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageHash + 2A 77A9438B 55 Bytes [ 01, 00, 53, 53, FF, 75, E0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 33 77A943C3 3 Bytes [ 46, 0C, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 37 77A943C7 41 Bytes [ E4, 89, 46, 04, 33, C0, 40, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 62 77A943F2 2 Bytes [ FC, 8B ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 65 77A943F5 40 Bytes [ 0C, 8B, 40, 10, 8B, 00, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessageWithKey + 8E 77A9441E 64 Bytes CALL B069C774
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 49 77A94598 65 Bytes [ 56, 8B, F1, 83, 66, 18, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 8B 77A945DA 100 Bytes [ 75, 08, FF, 15, 84, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + F0 77A9463F 12 Bytes [ 76, 04, FF, 36, FF, D0, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 127 77A94676 77 Bytes [ 10, 8B, 4D, 08, 83, 61, 0C, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignatureWithKey + 175 77A946C4 53 Bytes [ 71, 18, EB, 03, 8B, 71, 1C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 3B 77A94D0C 14 Bytes [ 46, 56, 89, 45, E0, E8, E9, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 4A 77A94D1B 1 Byte [ 40 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignMessage + 4C 77A94D1D 154 Bytes [ EB, 02, 33, C0, 3D, 01, AA, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 58 77A94DB8 95 Bytes [ FC, 8B, 4D, E0, 89, 7B, 40, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + B8 77A94E18 35 Bytes [ 51, 18, 89, 50, 04, 8B, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + F7 77A94E57 9 Bytes [ EB, 0C, FF, 75, E4, E8, 4F, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 101 77A94E61 130 Bytes [ 83, 65, E4, 00, 8B, 45, E4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSignAndEncryptMessage + 184 77A94EE4 39 Bytes [ 15, 4C, 12, A5, 77, 6A, 11, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyMessageSignature + 22 77A951F4 19 Bytes [ 08, FF, 15, 08, 12, A5, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptVerifyDetachedMessageSignature + 18 77A9521E 19 Bytes [ 0D, 53, FF, 15, 4C, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptMessage + 19 77A95255 15 Bytes [ 6A, 00, FF, 75, 10, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptMessage + 29 77A95265 11 Bytes [ 83, 7D, FC, 00, 75, 04, 33, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + A 77A95279 32 Bytes [ F0, 85, F6, 74, 21, 8D, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 31 77A952A0 54 Bytes [ C0, 5E, C9, C2, 0C, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 68 77A952D7 54 Bytes [ 1C, 8B, 4E, 20, 8B, C2, 83, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + 9F 77A9530E 7 Bytes [ 83, 7D, DC, 00, 8B, F8, 74 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecryptAndVerifyMessageSignature + A7 77A95316 3 Bytes [ FF, 75, DC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptDecodeMessage + D 77A95375 181 Bytes [ 1C, FF, 75, 18, FF, 75, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 84 77A9542B 21 Bytes CALL 77A963A5 C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 9A 77A95441 45 Bytes [ 00, 6A, 1C, 33, C0, 83, 3B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + C8 77A9546F 5 Bytes [ 89, B5, FC, FE, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + CE 77A95475 62 Bytes [ 72, 19, 8D, 73, 20, 8B, 06, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEncodeObject + 10D 77A954B4 7 Bytes [ 43, 08, 89, 85, 70, FF, FF ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + B 77A9B8B4 8 Bytes [ 0C, 8D, 47, 08, 50, E8, 22, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + 15 77A9B8BE 98 Bytes [ 8B, 4D, F8, 4E, 83, C7, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptGetOIDFunctionValue + 78 77A9B921 93 Bytes [ 8B, F0, 85, F6, 74, 29, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDFunction + 3B 77A9B97F 97 Bytes [ E1, F8, 2B, D1, 89, 75, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + F 77A9B9E1 18 Bytes [ 8B, 45, 18, 5F, 89, 30, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 22 77A9B9F4 98 Bytes [ 55, 8B, EC, 53, 8B, 5D, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 85 77A9BA57 25 Bytes [ 83, C6, 14, 85, FF, 77, D4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + 9F 77A9BA71 2 Bytes [ EC, 56 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDFunction + A2 77A9BA74 165 Bytes [ 75, 08, 8B, 46, 04, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + 77 77A9BBBE 11 Bytes [ 75, 18, FF, 75, 14, 50, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + 84 77A9BBCB 39 Bytes [ 8B, F0, 8D, 45, E0, 50, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + AC 77A9BBF3 32 Bytes [ C6, 5E, C9, C2, 1C, 00, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + CD 77A9BC14 23 Bytes [ FC, 79, 06, 83, 65, 14, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterDefaultOIDFunction + E5 77A9BC2C 27 Bytes [ 8B, 5D, 0C, 8B, 7D, 08, 8D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 37 77A9BCF0 76 Bytes CALL 7C20BC45 C:\Programmi\File comuni\Ahead\Lib\MFC71.DLL (MFCDLL Shared Library - Retail Version/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 84 77A9BD3D 44 Bytes [ 19, FF, 75, 20, 8D, 45, E8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + B1 77A9BD6A 21 Bytes CALL 77A9BA6A C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + C7 77A9BD80 126 Bytes [ FF, 55, 8B, EC, 51, 53, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterDefaultOIDFunction + 147 77A9BE00 18 Bytes [ FC, 89, 03, 5F, 33, C0, 5E, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDInfo + 4E 77A9BF71 4 Bytes [ 85, C0, 89, 42 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptRegisterOIDInfo + 53 77A9BF76 252 Bytes [ 89, 72, 08, 76, 10, 8B, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 9B 77A9C073 4 Bytes [ FF, 75, 14, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + F5 77A9C0CD 38 Bytes [ 80, 74, 05, 8B, 45, 1C, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 11C 77A9C0F4 2 Bytes [ F0, 8D ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 11F 77A9C0F7 26 Bytes CALL 77A9BA6B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptUnregisterOIDInfo + 13C 77A9C114 46 Bytes [ 8B, 10, 8B, 4D, 14, 56, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + 5E 77A9C4B6 64 Bytes [ FF, 85, C0, 74, 1C, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + 9F 77A9C4F7 4 Bytes [ 78, FC, 89, 38 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + A4 77A9C4FC 31 Bytes [ 55, FC, 8B, 52, 04, 8B, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + C4 77A9C51C 7 Bytes [ 0A, 72, D0, 8D, 45, F0, 89 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFindLocalizedName + CC 77A9C524 4 Bytes [ F8, FF, 75, 24 ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 29 77A9CEA7 50 Bytes [ 76, 04, FF, D7, 8B, D8, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 5C 77A9CEDA 24 Bytes [ 5F, 5B, EB, 0D, 68, 57, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 75 77A9CEF3 15 Bytes [ C9, C3, 90, 90, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 85 77A9CF03 21 Bytes [ 75, 14, FF, 75, 10, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptEnumOIDInfo + 9B 77A9CF19 20 Bytes [ FF, 5D, C2, 14, 00, 90, 90, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 9A 77A9D271 96 Bytes [ 75, 08, 56, FF, 55, 0C, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + FB 77A9D2D2 55 Bytes CALL C534D6C2
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 133 77A9D30A 10 Bytes [ 89, 75, F4, FF, D3, 8D, 44, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 13E 77A9D315 8 Bytes [ F0, 03, C6, 50, E8, 92, 81, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptFormatObject + 147 77A9D31E 92 Bytes [ 8B, D8, 85, DB, 0F, 84, 82, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 21 77AA5CF3 6 Bytes [ E4, 74, 05, FF, 75, E4 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 28 77AA5CFA 46 Bytes [ D6, 39, 5D, E0, 74, 05, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 57 77AA5D29 39 Bytes [ 75, F4, FF, D6, 39, 5D, FC, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 7F 77AA5D51 17 Bytes [ 55, 8B, EC, 81, EC, 3C, 04, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMemRealloc + 92 77AA5D64 112 Bytes [ FC, 8B, 45, 14, 53, 56, 33, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 15 77AA71B2 29 Bytes CALL 77A82D4D C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 33 77AA71D0 23 Bytes JMP 77AA725C C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + 4B 77AA71E8 112 Bytes [ 57, 57, 57, 6A, 02, 57, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + BD 77AA725A 33 Bytes [ F8, FF, D3, 5B, 8B, C6, 5E, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertProtectFunction + DF 77AA727C 71 Bytes [ 00, A1, 00, 51, AD, 77, 8B, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 17 77AA8398 1 Byte [ 4F ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 19 77AA839A 46 Bytes [ 43, 00, 20, 00, 4D, 00, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 49 77AA83CA 15 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 59 77AA83DA 1 Byte [ A1 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CertSrvProtectFunction + 5B 77AA83DC 40 Bytes [ 51, AD, 77, 53, 8B, 5D, 10, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUnregisterSmartCardStore + 2 77AA84C6 3 Bytes [ FF, 74, 1E ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptUnregisterSmartCardStore + 6 77AA84CA 77 Bytes [ B5, 64, FD, FF, FF, 50, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 34 77AA8518 16 Bytes [ FF, 00, 66, 83, A5, 6C, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 45 77AA8529 155 Bytes [ 8B, 46, 0C, 83, C0, 20, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + E1 77AA85C5 26 Bytes [ 83, 78, 04, 00, C7, 85, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + FC 77AA85E0 36 Bytes [ FF, 85, C0, 89, 85, 60, FD, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindSmartCardCertInStore + 121 77AA8605 14 Bytes [ 74, 3D, 8B, 95, 60, FD, FF, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 2 77AA866C 9 Bytes [ 85, C0, 74, 3B, FF, B5, 64, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + C 77AA8676 26 Bytes [ 8D, 85, 6C, FF, FF, FF, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 27 77AA8691 64 Bytes [ FF, FF, 50, 8D, 47, 04, 68, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 68 77AA86D2 3 Bytes [ 75, F1, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptAddSmartCardCertToStore + 6D 77AA86D7 11 Bytes [ 85, 68, FD, FF, FF, 8D, 1C, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptInstallOssGlobal + 19 77AA87C2 58 Bytes [ 50, 8D, 46, 14, 68, 1F, 25, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 32 77AA8822 110 Bytes [ 8D, 45, A4, 50, 75, 0A, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + A1 77AA8891 19 Bytes [ CA, 83, E1, 03, F3, A4, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + B5 77AA88A5 168 Bytes [ 33, C0, 81, 7D, 10, 1A, 18, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 242 77AA8A32 3 Bytes [ 83, 4D, FC ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetOssGlobal + 246 77AA8A36 34 Bytes [ FF, 75, E4, FF, 15, 4C, 12, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 7A 77AB1345 40 Bytes [ FF, 8D, 43, 5C, 50, 6A, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + A4 77AB136F 18 Bytes [ F6, 03, 80, 75, 04, 83, 63, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + B7 77AB1382 101 Bytes [ D6, F7, D8, 1B, C0, F7, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 11D 77AB13E8 57 Bytes [ 90, 90, 90, 90, 90, C2, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCalculateEncodedLength + 157 77AB1422 54 Bytes [ F0, 85, F6, 74, 2A, 8D, 45, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 18 77AB327B 83 Bytes [ 43, 04, 89, 45, EC, EB, 61, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 6C 77AB32CF 71 Bytes [ 75, D4, FF, 75, DC, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + B4 77AB3317 38 Bytes [ E4, 50, A5, 8D, 45, B4, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + DB 77AB333E 45 Bytes CALL 77A92B2B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgDuplicate + 109 77AB336C 124 Bytes CALL F52F0A70
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 3E 77AB4A21 29 Bytes [ 55, 8B, EC, 83, EC, 0C, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 5C 77AB4A3F 1 Byte [ 45 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + 5E 77AB4A41 69 Bytes [ 74, 1D, FF, 75, 10, FF, 75, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + A4 77AB4A87 29 Bytes [ 85, C0, 7D, 19, 68, 05, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgVerifyCountersignatureEncoded + C2 77AB4AA5 5 Bytes [ 75, 08, FF, 75, FC ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToEncode + 6 77AB8203 148 Bytes [ 45, F0, 89, 41, 08, 8B, 45, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgOpenToEncode + 9B 77AB8298 185 Bytes [ 8B, 43, 08, 89, 45, CC, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + CB 77AB8387 62 Bytes CALL CF1393FF
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 10A 77AB83C6 38 Bytes [ F8, 83, 3E, 24, 72, 1A, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 131 77AB83ED 203 Bytes [ 8B, 4E, 14, 03, CA, 03, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 1FD 77AB84B9 27 Bytes [ 4D, F4, 89, 41, 04, 03, 02, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgCountersign + 219 77AB84D5 43 Bytes [ 7E, 14, 00, 0F, 84, 87, 00, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetAndVerifySigner + 18 77AB85F8 81 Bytes [ 57, 2C, C7, 47, 30, 02, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgGetAndVerifySigner + 6A 77AB864A 144 Bytes [ 85, C0, 74, 19, 83, 7F, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 71 77AB8701 194 Bytes [ 55, 8B, EC, 83, EC, 14, 53, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 134 77AB87C4 37 Bytes [ 47, C7, 43, 30, 05, 00, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 15A 77AB87EA 75 Bytes [ 75, 18, 89, 43, 44, E8, DB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 1A6 77AB8836 33 Bytes [ FF, 3B, C7, 59, 74, 0A, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptMsgEncodeAndSignCTL + 1C8 77AB8858 10 Bytes [ C8, 3B, CF, 74, 12, 89, 79, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveProvider + D5 77ABDD53 112 Bytes [ C6, 5E, 5B, C9, C2, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 28 77ABDDC6 10 Bytes [ 00, 75, 35, 83, 7D, 08, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 33 77ABDDD1 19 Bytes [ 44, 00, 74, 04, A8, 40, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 48 77ABDDE6 1 Byte [ C7 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 4C 77ABDDEA 17 Bytes [ 6A, 00, 53, FF, 75, 0C, 56, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPAddProvider + 5E 77ABDDFC 106 Bytes [ 00, 00, 33, D2, 39, 55, 14, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 2F 77ABDF92 22 Bytes [ 74, 14, FF, 75, 08, 83, C7, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 46 77ABDFA9 4 Bytes [ 15, 08, 12, A5 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 4B 77ABDFAE 17 Bytes [ 89, 45, F8, 33, F6, EB, 03, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPPutSignedDataMsg + 5D 77ABDFC0 116 Bytes [ 5F, 8B, C6, 5E, 5B, C9, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveSignedDataMsg + 3D 77ABE035 17 Bytes [ 00, 56, 68, 67, BD, AB, 77, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRemoveSignedDataMsg + 4F 77ABE047 81 Bytes [ 00, 00, 50, 8D, 46, 78, 50, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPCreateIndirectData + 63 77ABE0E1 13 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPCreateIndirectData + 72 77ABE0F0 4 Bytes [ 35, 54, 50, AD ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + 70 77ABE17D 20 Bytes [ 62, 8B, 03, 89, 87, C4, 00, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + C7 77ABE1D4 6 Bytes [ 80, 4E, 7E, 01, 50, E8 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + CE 77ABE1DB 28 Bytes [ E2, FA, FF, EB, 10, 8B, 86, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + EB 77ABE1F8 36 Bytes [ 7D, 0C, 00, 74, 05, 0B, C2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptSIPRetrieveSubjectGuidForCatalogFile + 110 77ABE21D 100 Bytes [ EB, 0C, 83, 3F, 00, 75, 04, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 4E 77ABF104 149 Bytes [ C9, C2, 0C, 00, 90, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + E4 77ABF19A 14 Bytes CALL 77A82D4B C:\WINDOWS\system32\CRYPT32.dll (Crypto API32/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + F3 77ABF1A9 14 Bytes [ 0F, 84, 1B, 01, 00, 00, 89, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 102 77ABF1B8 40 Bytes [ FF, 75, BC, FF, 15, 54, 13, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptImportPKCS8 + 12C 77ABF1E2 48 Bytes [ C0, 56, FF, 15, AC, 12, A5, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 77ABF2F9 64 Bytes [ 90, 33, C0, 40, C3, 90, 90, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 42 77ABF33B 11 Bytes [ FF, A3, E2, AB, 77, B6, E2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 4E 77ABF347 68 Bytes [ FF, FA, E2, AB, 77, 03, E3, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + 94 77ABF38D 24 Bytes [ F4, 89, 5D, F8, 89, 5D, F0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CryptExportPKCS8 + AD 77ABF3A6 13 Bytes [ 45, 0C, 53, FF, 75, 10, 25, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + D 77ABF755 20 Bytes [ 45, F4, 50, FF, 75, EC, 57, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 23 77ABF76B 4 Bytes [ 00, 8D, 45, FF ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 28 77ABF770 14 Bytes [ 75, D0, 89, 45, D4, 89, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXImportCertStore + 38 77ABF780 452 Bytes [ 75, 06, C6, 45, FF, 80, EB, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + 9E 77ABF945 12 Bytes [ 34, 30, FF, 15, E4, 12, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + AB 77ABF952 13 Bytes [ 47, 04, 8B, 44, 06, 08, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + B9 77ABF960 18 Bytes [ FF, 30, FF, 70, 04, 6A, 1A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + CD 77ABF974 89 Bytes [ F8, 6A, 00, FF, 15, 64, 12, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStore + 127 77ABF9CE 214 Bytes [ FF, FF, EB, 10, C7, 45, F4, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 37 77ABFAA5 26 Bytes [ 00, 74, 09, FF, 75, FC, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 52 77ABFAC0 7 Bytes [ 5E, 8B, C3, 5B, C9, C2, 10 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 5A 77ABFAC8 12 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 67 77ABFAD5 19 Bytes [ 5D, 08, 53, 6A, 00, FF, 15, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!PFXExportCertStoreEx + 7B 77ABFAE9 204 Bytes [ 0F, 84, E7, 00, 00, 00, 56, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCertificateChain + 9A 77AC9FBD 21 Bytes [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertDuplicateCertificateChain + B3 77AC9FD6 18 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertFreeCertificateChainEngine + 6 77ACA01C 57 Bytes [ F1, 8B, FA, 75, 03, 6A, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 14 77ACA056 22 Bytes [ DD, F6, 06, 80, 74, 1E, 8B, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 2B 77ACA06D 39 Bytes [ 00, 80, 57, FF, 15, 10, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 53 77ACA095 22 Bytes [ 55, 8B, EC, 83, EC, 0C, 85, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 6A 77ACA0AC 2 Bytes [ 51, 50 ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CertResyncCertificateChainEngine + 6D 77ACA0AF 31 Bytes [ 75, 08, FF, 15, 6C, 14, A5, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!ChainWlxLogoffEvent 77ACA134 103 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 29 77ACA19C 19 Bytes [ 15, 54, 14, A5, 77, F7, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 3F 77ACA1B2 15 Bytes [ 8B, FF, 55, 8B, EC, 51, 51, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 4F 77ACA1C2 30 Bytes [ 58, 8D, 4D, F8, 51, 8D, 4D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptGetLruEntryIdentifier + 6E 77ACA1E1 88 Bytes [ FE, AA, 8D, 46, 04, 50, 6A, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 12 77ACA23A 17 Bytes [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 30 77ACA258 74 Bytes [ 56, 8B, 75, 08, 85, F6, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 7B 77ACA2A3 16 Bytes [ FF, 55, 8B, EC, FF, 75, 10, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + 8C 77ACA2B4 67 Bytes [ FF, F7, D8, 1B, C0, F7, D8, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptFindLruEntryData + D0 77ACA2F8 18 Bytes [ 15, 58, 14, A5, 77, 85, C0, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + F 77ACA329 29 Bytes [ 75, 0C, 57, FF, 15, 54, 14, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 2D 77ACA347 64 Bytes [ EC, 51, 8B, 45, 0C, 85, C0, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 7F 77ACA399 27 Bytes [ 75, 08, FF, 15, 5C, 14, A5, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + 9B 77ACA3B5 40 Bytes [ EC, 8B, 45, 08, 85, C0, 74, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!I_CryptEnableLruOfEntries + C4 77ACA3DE 8 Bytes [ 15, C4, 14, A5, 77, 5E, 5D, ... ]
.text ...
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!OpenCertPerformanceData + A1 77ACEC90 13 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!OpenCertPerformanceData + AF 77ACEC9E 191 Bytes [ 53, 56, 57, 76, 36, 8B, 5D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 14 77ACED5E 117 Bytes [ 4D, FC, 75, 0E, 8B, 45, 08, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 8A 77ACEDD4 121 Bytes [ 45, 08, 8B, 50, 34, 85, D2, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 105 77ACEE4F 23 Bytes [ 85, DB, 6A, 0F, 59, 8B, FE, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 11D 77ACEE67 43 Bytes [ 89, 5E, 04, 89, 46, 08, 8D, ... ]
.text C:\WINDOWS\Explorer.EXE[240] CRYPT32.dll!CollectCertPerformanceData + 149 77ACEE93 65 Bytes [ 10, 59, 59, FF, 30, FF, 15, ... ]
.text ...
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 003A87C1
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 003A8779
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 003A62D9
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 003A6D09
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CloseHandle] 003A7C09
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 003A6E59
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 003A6D4E
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileW] 003A7629
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 003A84FC
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalLock] 003A852C
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 003A8836
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 003A8401
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 003A7B99
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] 003A71D1
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 003A6E0B
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 003A7011
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 003A8B62
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!ReadFile] 003A7828
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 003A7A95
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 003A7E8D
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 003A7D22
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 003A7E3B
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 003A80C7
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 003A7F85
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] 003A6DBD
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 003A7126
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 003A85D7
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 003A7DE4
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileSize] 003A7B4C
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!WriteFile] 003A7A65
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileType] 003A7C99
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetACP] 003A8842
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingA] 003A7CB9
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadIconW] 003A89C7
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadCursorW] 003A8995
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateDialogParamW] 003A8AEA
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DialogBoxParamW] 003A8B46
IAT C:\Programmi\GetRight\GetRight.exe[268] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadStringW] 003A8A33
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 89B78FB0
AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
Device \FileSystem\Fastfat \FatCdrom 899370D8
Device \FileSystem\Udfs \UdfsCdRom 898721D0
Device \FileSystem\Udfs \UdfsDisk 898721D0
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\Rdbss \Device\FsWrap 897D5C00
Device \Driver\atapi \Device\Ide\IdePort0 897AE008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 897AE008
Device \Driver\atapi \Device\Ide\IdePort1 897AE008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 897AE008
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 897AE008
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 897AE008
Device \Driver\USBSTOR \Device\00000080 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000081 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000082 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000083 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\USBSTOR \Device\00000084 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Srv \Device\LanmanServer 8989E618
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 897D6390
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 897D6390
Device \FileSystem\Npfs \Device\NamedPipe 8981A250
Device \FileSystem\Msfs \Device\Mailslot 897D5E18
Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 897D5CE8
Device \Driver\a347scsi \Device\Scsi\a347scsi1 897D5CE8
Device \FileSystem\Fastfat \Fat 899370D8
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8990C030
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8990C030
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8990C030
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8990C030
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8990C030
Device \FileSystem\Cdfs \Cdfs 899466B8
---- Modules - GMER 1.0.14 ----
Module _________ F73A2000-F73BA000 (98304 bytes)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}@DisplayName Alcohol 120% (Trial Version)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Abaddon\x2122 (TrueType) abaddon.TTF
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Acadian\x2122 (TrueType) AC______.TTF
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Altenburg\x2122 (TrueType) ALTEN.TTF
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Asphodel\x2122 (TrueType) ASPHODEL.TTF
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Balsamo\x2122 (TrueType) BALSAMO.TTF
Reg HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6@ProductName Alcohol 120% (Trial Version)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}@nakcaiaganokclohnffjminfbaih 0x6B 0x61 0x6E 0x61 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6AC5798-BE26-6D2A-2C04-387A78493BE0}@maicggelnnkgakdnnoackakloe 0x6B 0x61 0x6E 0x61 ...
---- EOF - GMER 1.0.14 ----
__________________
Se dio avesse voluto che credessimo in lui sarebbe esistito. Principale: Q6600 (Zalman 9500) - 4core1600twins-sataII - ddr800 2x2gb - Sapphire HD4870 - HP w2207. Mulettino: A64 3000+ (Zalman 9500) - K8nf4g-sataII - ddr400 2x1gb Vdata |
|
|
|
|
|
#144 |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 2171
|
doppio post
__________________
Se dio avesse voluto che credessimo in lui sarebbe esistito. Principale: Q6600 (Zalman 9500) - 4core1600twins-sataII - ddr800 2x2gb - Sapphire HD4870 - HP w2207. Mulettino: A64 3000+ (Zalman 9500) - K8nf4g-sataII - ddr400 2x1gb Vdata |
|
|
|
|
|
#145 |
|
Junior Member
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
|
secondo voi è tutto a posto......
http://www.fileup.itadib.com/downloa...tzKQ3wPGAnQw2F |
|
|
|
|
|
#146 | ||
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Quote:
Quote:
Ti suggerisco di seguire la Guida alla disinfezione allegando i log prodotti in un'unico post secondo le sottoindicate modalità, grazie per la collaborazione MODALITA' DI PUBBLICAZIONE DEI LOG RICHIESTI: Ogni singolo log, esclusivamente in formato txt, deve essere hostato su MediaFire, pubblicando, nella discussione, singolarmente, per ogni log, il link che verrà rilasciato per il download Dopo aver prodotto i log apri una nuova discussione qui: http://www.hwupgrade.it/forum/forumdisplay.php?f=125 Ciao
__________________
Try again and you will be luckier.
|
||
|
|
|
|
|
#147 | |
|
Junior Member
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
|
Quote:
|
|
|
|
|
|
|
#148 |
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Segui la Guida che ti ho linkato, ma il log di Gmer l'hai fatto per controllo oppure riscontri problemi?
__________________
Try again and you will be luckier.
|
|
|
|
|
|
#149 |
|
Junior Member
Iscritto dal: Apr 2008
Città: Piemonte
Messaggi: 18
|
per controllo
|
|
|
|
|
|
#150 |
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
Io un controllo con i tool indicati in Guida lo farei
__________________
Try again and you will be luckier.
|
|
|
|
|
|
#151 | |
|
Member
Iscritto dal: Apr 2008
Messaggi: 104
|
re
Quote:
e unisco alla lista anche HIJACKFREE della stessa "casa" di hijackthis.. per alcuni versi simile a Gmer. esiste un thread ufficiale di HiJackFree ? |
|
|
|
|
|
|
#152 |
|
Senior Member
Iscritto dal: Dec 2007
Città: prov. RA
Messaggi: 568
|
Volevo chiedervi 2-3 cose:
La scansione di Gmer non mi ha rilevato rootkit mentre quella di rootkit revealer ne ha rilevate 4 (lui le chiama discrepanze, scritto in inglese ovviamente); immagino siano rootkit, vero? Un'altra cosa: vi risulta che nella schermata di gmer i pulsanti Scan, Copy e Save anzichè essere in basso a destra siano poco sopra, finendo per coprire il rettangolino dove dentro si trova casella di spunta con a fianco "C:\"? Nella versione precedente non succedeva; ho provato a riscaricarlo ma non è cambiato niente. Boh!
__________________
Andrea |
|
|
|
|
|
#153 |
|
Junior Member
Iscritto dal: Jul 2008
Messaggi: 9
|
mi leggereste questo log? grazie anticipatamente
Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-03 03:39:27
Windows 6.0.6001 Service Pack 1
---- User code sections - GMER 1.0.14 ----
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[3756] kernel32.dll!SetUnhandledExceptionFilter 762D6E2D 5 Bytes JMP 0056DBBD C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation)
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestione filtri file system Microsoft/Microsoft Corporation)
---- EOF - GMER 1.0.14 ----
GMER 1.0.14.14536 - http://www.gmer.net
Autostart scan 2008-07-03 03:40:53
Windows 6.0.6001 Service Pack 1
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * lsdelete /*file not found*/
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\Windows\system32\userinit.exe, = C:\Windows\system32\userinit.exe,
@Shellexplorer.exe = explorer.exe
@GinaDLLvrlogon.dll = vrlogon.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
igfxcui@DLLName = igfxdev.dll
psfus@DLLName = C:\Windows\system32\psqlpwd.dll
VESWinlogon@DLLName = VESWinlogon.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs =
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
a2free@ = "C:\Program Files\a-squared Free\a2service.exe"
aawservice@ = "C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe"
AeLookupSvc@ = %systemroot%\system32\svchost.exe -k netsvcs
AntiVirScheduler@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"
AntiVirService@ = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"
AudioEndpointBuilder@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
Audiosrv@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
BFE@ = %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
BITS@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Browser@ = %SystemRoot%\System32\svchost.exe -k netsvcs
CLTNetCnService@ = "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon /*file not found*/
CryptSvc@ = %SystemRoot%\system32\svchost.exe -k NetworkService
DcomLaunch@ = %SystemRoot%\system32\svchost.exe -k DcomLaunch
Dhcp@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
Dnscache@ = %SystemRoot%\system32\svchost.exe -k NetworkService
DPS@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
EMDMgmt@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
Eventlog@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
EventSystem@ = %SystemRoot%\system32\svchost.exe -k LocalService
FDResPub@ = %SystemRoot%\system32\svchost.exe -k LocalService
gpsvc@ = %windir%\system32\svchost.exe -k GPSvcGroup
IKEEXT@ = %systemroot%\system32\svchost.exe -k netsvcs
iphlpsvc@ = %SystemRoot%\System32\svchost.exe -k NetSvcs
KtmRm@ = %SystemRoot%\System32\svchost.exe -k NetworkService
LanmanServer@ = %SystemRoot%\system32\svchost.exe -k netsvcs
LanmanWorkstation@ = %SystemRoot%\System32\svchost.exe -k LocalService
lmhosts@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
MMCSS@ = %SystemRoot%\system32\svchost.exe -k netsvcs
MpsSvc@ = %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
netprofm@ = %SystemRoot%\System32\svchost.exe -k LocalService
NlaSvc@ = %SystemRoot%\System32\svchost.exe -k NetworkService
NMSAccessU@ = C:\Program Files\CDBurnerXP\NMSAccessU.exe
nsi@ = %systemroot%\system32\svchost.exe -k LocalService
PcaSvc@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
PLFlash DeviceIoControl Service@ = C:\Windows\system32\IoctlSvc.exe /*file not found*/
PlugPlay@ = %SystemRoot%\system32\svchost.exe -k DcomLaunch
PolicyAgent@ = %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
ProfSvc@ = %systemroot%\system32\svchost.exe -k netsvcs
RapiMgr@ = %SystemRoot%\system32\svchost.exe -k WindowsMobile
RpcSs@ = %SystemRoot%\system32\svchost.exe -k rpcss
SamSs@ = %SystemRoot%\system32\lsass.exe
Schedule@ = %systemroot%\system32\svchost.exe -k netsvcs
seclogon@ = %windir%\system32\svchost.exe -k netsvcs
SENS@ = %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess@ = %SystemRoot%\System32\svchost.exe -k netsvcs
ShellHWDetection@ = %SystemRoot%\System32\svchost.exe -k netsvcs
slsvc@ = %SystemRoot%\system32\SLsvc.exe
Spooler@ = %SystemRoot%\System32\spoolsv.exe
stisvc@ = %SystemRoot%\system32\svchost.exe -k imgsvc
SysMain@ = %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
TabletInputService@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
TBS@ = %SystemRoot%\System32\svchost.exe -k LocalService
Themes@ = %SystemRoot%\System32\svchost.exe -k netsvcs
TOSHIBA Bluetooth Service@ = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
TrkWks@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
upnphost@ = %SystemRoot%\system32\svchost.exe -k LocalService
UxSms@ = %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
VAIO Event Service@ = C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
VzCdbSvc@ = "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"
VzFw@ = C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
W32Time@ = %SystemRoot%\system32\svchost.exe -k LocalService
WcesComm@ = %SystemRoot%\system32\svchost.exe -k WindowsMobile
WebClient@ = %SystemRoot%\system32\svchost.exe -k LocalService
WerSvc@ = %SystemRoot%\System32\svchost.exe -k WerSvcGroup
WinDefend@ = %SystemRoot%\System32\svchost.exe -k secsvcs
Winmgmt@ = %systemroot%\system32\svchost.exe -k netsvcs
Wlansvc@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
WPDBusEnum@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
wscsvc@ = %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
wuauserv@ = %systemroot%\system32\svchost.exe -k netsvcs
wudfsvc@ = %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
XAudioService@ = %SystemRoot%\system32\DRIVERS\xaudio.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ApointC:\Program Files\Apoint\Apoint.exe = C:\Program Files\Apoint\Apoint.exe
@DRCU"C:\Program Files\Sony\DRCU\DRCU.exe" = "C:\Program Files\Sony\DRCU\DRCU.exe"
@ISBMgr.exe"C:\Program Files\Sony\ISB Utility\ISBMgr.exe" = "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
@PSQLLauncher"C:\Program Files\Protector Suite QL\launcher.exe" /startup = "C:\Program Files\Protector Suite QL\launcher.exe" /startup
@Windows Mobile-based device management%windir%\WindowsMobile\wmdSync.exe = %windir%\WindowsMobile\wmdSync.exe
@NvCplDaemonRUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
@NvMediaCenterRUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
@avgnt"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
@SunJavaUpdateSched"C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" = "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
@NBKeyScan"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" /*file not found*/ = "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" /*file not found*/
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce >>>
@COMODO Firewall Pro"C:\Program Files\COMODO\Firewall\cfpconfg.exe" -z -o /*file not found*/ = "C:\Program Files\COMODO\Firewall\cfpconfg.exe" -z -o /*file not found*/
@AskSBar Uninstallrundll32 C:\PROGRA~1\UNINST~1.DLL,O -3 = rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3
HKCU\Software\Microsoft\Windows\CurrentVersion\Run@Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun /*file not found*/
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WebCheck = C:\Windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler@{8C7461EF-2B13-11d2-BE35-3078302C2030} = %SystemRoot%\system32\browseui.dll
HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L
HKLM\Software\Classes\ >>>
.exe@ = "%1" %*
.com@ = "%1" %*
.cmd@ = "%1" %*
.bat@ = "%1" %*
.pif@ = "%1" %*
.scr@ = "%1" /S
.hta@ = C:\Windows\system32\mshta.exe "%1" %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/%CommonProgramFiles%\System\Ole DB\oledb32.dll /*file not found*/ = %CommonProgramFiles%\System\Ole DB\oledb32.dll /*file not found*/
@{F02C1A0D-BE21-4350-88B0-7367FC96EF3C} /*Computers and Devices*/%systemroot%\system32\NetworkExplorer.dll = %systemroot%\system32\NetworkExplorer.dll
@{E7DE9B1A-7533-4556-9484-B26FB486475E} /**/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{7A80E4A8-8005-11D2-BCF8-00C04F72C717} /*MMC Icon Handler*/%SystemRoot%\system32\mmcshext.dll = %SystemRoot%\system32\mmcshext.dll
@{08165EA0-E946-11CF-9C87-00AA005127ED} /*WebCheckWebCrawler*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7D559C10-9FE9-11d0-93F7-00AA0059CE02} /*Code Download Agent*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} /*WebCheck SyncMgr Handler*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} /*Subscription Mgr*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{F5175861-2688-11d0-9C5E-00AA00A45957} /*Subscription Folder*/C:\Windows\system32\webcheck.dll = C:\Windows\system32\webcheck.dll
@{7007ACC7-3202-11D1-AAD2-00805FC1270E} /*Network Connections*/%SystemRoot%\System32\netshell.dll = %SystemRoot%\System32\netshell.dll
@{992CFFA0-F557-101A-88EC-00DD010CCC48} /*Network Connections*/%SystemRoot%\System32\netshell.dll = %SystemRoot%\System32\netshell.dll
@{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486} /*IGD Property Sheet Handler*/%SystemRoot%\System32\icsigd.dll = %SystemRoot%\System32\icsigd.dll
@{92dbad9f-5025-49b0-9078-2d78f935e341} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{b9815375-5d7f-4ce2-9245-c9d4da436930} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{f8b8412b-dea3-4130-b36c-5e8be73106ac} /*Microsoft Windows Mail Html Preview Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{5FA29220-36A1-40f9-89C6-F4B384B7642E} /*Shell Message Handler*/%SystemRoot%\system32\inetcomm.dll = %SystemRoot%\system32\inetcomm.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{8856f961-340a-11d0-a96b-00c04fd705a2} /*Microsoft Web Browser*/C:\Windows\system32\ieframe.dll = C:\Windows\system32\ieframe.dll
@{3050f3d9-98b5-11cf-bb82-00aa00bdce0b} /*MSHTML Document*/C:\Windows\system32\mshtml.dll = C:\Windows\system32\mshtml.dll
@{25336920-03f9-11cf-8fd0-00aa00686f13} /*HTML Document*/C:\Windows\system32\mshtml.dll = C:\Windows\system32\mshtml.dll
@{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} /*Mail Service*/%SystemRoot%\System32\sendmail.dll = %SystemRoot%\System32\sendmail.dll
@{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} /*Desktop Shortcut*/%SystemRoot%\System32\sendmail.dll = %SystemRoot%\System32\sendmail.dll
@{CC6EEFFB-43F6-46c5-9619-51D571967F7D} /*Web Publishing Wizard*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{add36aa8-751a-4579-a266-d66f5202ccbb} /*Print Ordering via the Web*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{6b33163c-76a5-4b6c-bf21-45de9cd503a1} /*Shell Publishing Wizard Object*/%SystemRoot%\System32\shwebsvc.dll = %SystemRoot%\System32\shwebsvc.dll
@{176d6597-26d3-11d1-b350-080036a75b03} /*ICM Scanner Management*/%SystemRoot%\System32\colorui.dll = %SystemRoot%\System32\colorui.dll
@{5DB2625A-54DF-11D0-B6C4-0800091AA605} /*ICM Monitor Management*/%SystemRoot%\System32\colorui.dll = %SystemRoot%\System32\colorui.dll
@{675F097E-4C4D-11D0-B6C1-0800091AA605} /*ICM Printer Management*/%SystemRoot%\system32\colorui.dll = %SystemRoot%\system32\colorui.dll
@{DBCE2480-C732-101B-BE72-BA78E9AD5B27} /*ICC Profile*/%SystemRoot%\system32\colorui.dll = %SystemRoot%\system32\colorui.dll
@{b2c761c6-29bc-4f19-9251-e6195265baf1} /*Color Control Panel Applet*/(null) =
@{0D45D530-764B-11d0-A1CA-00AA00C16E65} /*Directory Property UI*/%systemroot%\system32\dsuiext.dll = %systemroot%\system32\dsuiext.dll
@{62AE1F9A-126A-11D0-A14B-0800361B1103} /*Directory Context Menu Verbs*/%systemroot%\system32\dsuiext.dll = %systemroot%\system32\dsuiext.dll
@{8A23E65E-31C2-11d0-891C-00A024AB2DBB} /*Directory Query UI*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} /*Shell properties for a DS object*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} /*Directory Object Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F020E586-5264-11d1-A532-0000F8757D7E} /*Directory Start/Search Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} /*Printers Security Page*/rshx32.dll = rshx32.dll
@{1F2E5C40-9550-11CE-99D2-00AA006E086C} /*NTFS Security Page*/rshx32.dll = rshx32.dll
@{40dd6e20-7c17-11ce-a804-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{77597368-7b15-11d0-a0c2-080036af3f03} /*Web Printer Shell Extension*/%systemroot%\system32\printui.dll = %systemroot%\system32\printui.dll
@{4E40F770-369C-11d0-8922-00A024AB2DBB} /*DS Security Page*/dssec.dll = dssec.dll
@{41E300E0-78B6-11ce-849B-444553540000} /*PlusPack CPL Extension*/%SystemRoot%\system32\themeui.dll = %SystemRoot%\system32\themeui.dll
@{36eef7db-88ad-4e81-ad49-0e313f0c35f8} /*Windows Update*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{74246bfc-4c96-11d0-abef-0020af6b0b7a} /*Device Manager*/%SystemRoot%\System32\devmgr.dll = %SystemRoot%\System32\devmgr.dll
@{7A979262-40CE-46ff-AEEE-7884AC3B6136} /*Add New Hardware*/(null) =
@{7b81be6a-ce2b-4676-a29e-eb907a5126c5} /*Programs and Features*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{15eae92e-f17a-4431-9f28-805e482dafd4} /*Install New Programs*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd} /*Installed Updates*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{ceefea1b-3e29-4ef1-b34c-fec79c4f70af} /*New Shortcut Wizard*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{0BFCF7B7-E7B6-433a-B205-2904FCF040DD} /*New Shortcut Wizard Modal*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{CFCCC7A0-A282-11D1-9082-006008059382} /*Darwin App Publisher*/%SystemRoot%\System32\appwiz.cpl = %SystemRoot%\System32\appwiz.cpl
@{3e7efb4c-faf1-453d-89eb-56026875ef90} /*Get Programs Online*/(null) =
@{59099400-57FF-11CE-BD94-0020AF85B590} /*Disk Copy Extension*/diskcopy.dll = diskcopy.dll
@{ECF03A32-103D-11d2-854D-006008059367} /*MyDocs Drop Target*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{4a7ded0a-ad25-11d0-98a8-0800361b1103} /*MyFolder Properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{44f3dab6-4392-4186-bb7b-6282ccb7a9f6} /*MyDocuments menu and properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{0DF44EAA-FF21-4412-828E-260A8728E7F1} /*Taskbar and Start Menu*/(null) =
@{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} /*Search*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} /*Run...*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} /*Internet*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} /*E-mail*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0} /*Start Menu OEM Command*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} /*Set Program Access and Defaults*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3080F90D-D7AD-11D9-BD98-0000947B0257} /*Show Desktop*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3080F90E-D7AD-11D9-BD98-0000947B0257} /*Window Switcher*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{eb124705-128b-40d4-8dd8-d93ed12589a4} /*WPL property store*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{3c2654c6-7372-4f6b-b310-55d6128f49d2} /*Alphabetical Categorizer*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{9DBD2C50-62AD-11d0-B806-00C04FD706EC} /*Summary Info Thumbnail handler (DOCFILES)*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{708e1662-b832-42a8-bbe1-0a77121e3908} /*Tree property value folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{71f96385-ddd6-48d3-a0c1-ae06e8b055fb} /*Explorer Browser*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{b2952b16-0e07-4e5a-b993-58c52cb94cae} /*Search Folders*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{437ff9c0-a07f-4fa0-af80-84b6c6440a16} /*Command Folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{90f8c90b-04e0-4e92-a186-e6e9c125d664} /*Property Labels*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{1b24a030-9b20-49bc-97ac-1be4426f9e59} /*ActiveDirectory Folder*/(null) =
@{34449847-FD14-4fc8-A75A-7432F5181EFB} /*ActiveDirectory Folder*/(null) =
@{C8494E42-ACDD-4739-B0FB-217361E4894F} /*Sam Account Folder*/(null) =
@{E29F9716-5C08-4FCD-955A-119FDB5A522D} /*Sam Account Folder*/(null) =
@{D20EA4E1-3957-11d2-A40B-0C5020524152} /*Fonts*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524153} /*Administrative Tools*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{b155bdf8-02f0-451e-9a26-ae317cfd7779} /*nethood delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{DFFACDC5-679F-4156-8947-C5C76BC0B67F} /*users files delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{ed50fc29-b964-48a9-afb3-15ebb9b97f36} /*printhood delegate folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{328B0346-7EAF-4BBE-A479-7CB88A095F5B} /*Layout Folder*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} /*Control Panel command object for Start menu*/(null) =
@{E44E5D18-0652-4508-A4E2-8A090067BCB0} /*Default Programs command object for Start menu*/(null) =
@{4336a54d-038b-4685-ab02-99bb52d3fb8b} /*Public Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{00021401-0000-0000-C000-000000000046} /*Shortcut*/shell32.dll = shell32.dll
@{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9} /*Search Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B} /*.fon, .otf, .ttc or .ttf files*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{66742402-F9B9-11D1-A202-0000F81FEDEE} /*.cpl, .dll, .exe, .ocx, .rll or .sys files*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{D34A6CA6-62C2-4C34-8A7C-14709C1AD938} /*Common Places Folder*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{865e5e76-ad83-4dca-a109-50dc2113ce9a} /*Programs Folder and Fast Items*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{21ec2020-3aea-1069-a2dd-08002b30309d} /*Control Panel*/shell32.dll = shell32.dll
@{25585dc7-4da0-438d-ad04-e42c8d2d64b9} /*Client application shell extension*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{6dfd7c5c-2451-11d3-a299-00c04f8ef6af} /*Folder Options*/(null) =
@{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3} /*Microsoft Windows RTF Preview Handler*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{1531d583-8375-4d3f-b5fb-d23bbd169f22} /*Window TXT Preview Handler*/%SystemRoot%\system32\shell32.dll = %SystemRoot%\system32\shell32.dll
@{97e467b4-98c6-4f19-9588-161b7773d6f6} /*Office Document Property Handler*/%SystemRoot%\system32\propsys.dll = %SystemRoot%\system32\propsys.dll
@{88C6C381-2E85-11D0-94DE-444553540000} /*ActiveX Cache Folder*/C:\Windows\system32\occache.dll = C:\Windows\system32\occache.dll
@{5E6AB780-7743-11CF-A12B-00AA004AE837} /*Microsoft Internet Toolbar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7BA4C742-9E81-11CF-99D3-00AA004AE837} /*Microsoft BrowserBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{056440FD-8568-48e7-A632-72157243B55B} /*Explorer Navigation Bar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980} /*Explorer Travel Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F} /*Explorer Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{2C2577C2-63A7-40e3-9B7F-586602617ECB} /*Explorer Query Band*/(null) =
@{21569614-B795-46b1-85F4-E737A8DC09AD} /*Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{169A0691-8DF9-11d1-A1C4-00C04FD75D13} /*In-pane search*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{AF4F6510-F982-11d0-8595-00AA004CD6D8} /*Registry Tree Options Utility*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{01E04581-4EEE-11d0-BFE9-00AA005B4383} /*&Address*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{a542e116-8088-4146-a352-b0d06e7f6af6} /*Address EditBox*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{F61FFEC1-754F-11d0-80CA-00AA005B4383} /*BandProxy*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2763-6A77-11D0-A535-00C04FD7D062} /*Microsoft AutoComplete*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{596742A5-1393-4e13-8765-AE1DF71ACAFB} /*Microsoft Breadcrumb Bar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6756A641-DE71-11d0-831B-00AA005B4383} /*MRU AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} /*Custom MRU AutoCompleted List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2764-6A77-11D0-A535-00C04FD7D062} /*Microsoft History AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{03C036F1-A186-11D0-824A-00AA005B4383} /*Microsoft Shell Folder AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2765-6A77-11D0-A535-00C04FD7D062} /*Microsoft Multiple AutoComplete List Container*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4E-521C-11D0-B792-00A0C90312E1} /*Shell Band Site Menu*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} /*Shell DeskBarApp*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4D-521C-11D0-B792-00A0C90312E1} /*Shell Rebar BandSite*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DD313E04-FEFF-11d1-8ECD-0000F87A470C} /*User Assist*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} /*Global Folder Settings*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff} /*Search Control*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{4d5c8c2a-d075-11d0-b416-00c04fb90376} /*Microsoft CommBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7} /*File Open Dialog*/%SystemRoot%\System32\comdlg32.dll = %SystemRoot%\System32\comdlg32.dll
@{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B} /*File Save Dialog*/%SystemRoot%\System32\comdlg32.dll = %SystemRoot%\System32\comdlg32.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\Windows\system32\dfshim.dll = C:\Windows\system32\dfshim.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\Windows\system32\dfshim.dll = C:\Windows\system32\dfshim.dll
@{92337A8C-E11D-11D0-BE48-00C04FC30DF6} /*OlePrn.PrinterURL*/%SystemRoot%\system32\oleprn.dll = %SystemRoot%\system32\oleprn.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft XPS Properties*/%SystemRoot%\system32\XPSSHHDR.DLL = %SystemRoot%\system32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft XPS Thumbnail*/%SystemRoot%\system32\XPSSHHDR.DLL = %SystemRoot%\system32\XPSSHHDR.DLL
@{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b} /*View Available Networks*/(null) =
@{13D3C4B8-B179-4ebb-BF62-F704173E7448} /*Windows Contact Preview Handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{32714800-2E5F-11d0-8B85-00AA0044F941} /*For &People...*/%ProgramFiles%\Windows Mail\wabfind.dll /*file not found*/ = %ProgramFiles%\Windows Mail\wabfind.dll /*file not found*/
@{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} /*Contacts folder*/(null) =
@{4F58F63F-244B-4c07-B29F-210BE59BE9B4} /*.group shell extension handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{8082C5E6-4C27-48ec-A809-B8E1122E8F97} /*.contact shell extension handler*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{16C2C29D-0E5F-45f3-A445-03E03F587B7D} /*group_wab_auto_file*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{CF67796C-F57F-45F8-92FB-AD698826C602} /*contact_wab_auto_file*/%CommonProgramFiles%\System\wab32.dll = %CommonProgramFiles%\System\wab32.dll
@{7444C717-39BF-11D1-8CD9-00C04FC29D45} /*Crypto PKO Extension*/%SystemRoot%\system32\cryptext.dll = %SystemRoot%\system32\cryptext.dll
@{7444C719-39BF-11D1-8CD9-00C04FC29D45} /*Crypto Sign Extension*/%SystemRoot%\system32\cryptext.dll = %SystemRoot%\system32\cryptext.dll
@{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} /*Compatibility Property Page*/%windir%\system32\acppage.dll = %windir%\system32\acppage.dll
@{F0152790-D56E-4445-850E-4F3117DB740C} /*Remote Sessions CPL Extension*/%SystemRoot%\system32\remotepg.dll = %SystemRoot%\system32\remotepg.dll
@{4026492f-2f69-46b8-b9bf-5654fc07e423} /*Windows Firewall*/(null) =
@{D555645E-D4F8-4c29-A827-D93C859C4F2A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\Windows\system32\extmgr.dll = C:\Windows\system32\extmgr.dll
@{60254CA5-953B-11CF-8C96-00AA00B8708C} /*Shell extensions for Windows Script Host*/C:\Windows\system32\wshext.dll = C:\Windows\system32\wshext.dll
@{fcfeecae-ee1b-4849-ae50-685dcf7717ec} /*Problem Reports and Solutions*/(null) =
@{a304259d-52b8-4526-8b1a-a1d6cecc8243} /*iSCSI Initiator*/(null) =
@{8E908FC9-BECC-40f6-915B-F4CA0E70D03D} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{143A62C8-C33B-11D1-84FE-00C04FA34A14} /*Microsoft Agent Character Property Sheet Handler*/%SystemRoot%\MSAgent\agentpsh.dll = %SystemRoot%\MSAgent\agentpsh.dll
@{025A5937-A6BE-4686-A844-36FE4BEC8B6D} /*Microsoft Power Options*/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{BB06C0E4-D293-4f75-8A90-CB05B6477EEE} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{17cd9488-1228-4b2f-88ce-4298e93e0966} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{60632754-c523-4b62-b45c-4172da012619} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9C60DE1E-E5FC-40f4-A487-460851A8D915} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{42071712-76d4-11d1-8b24-00a0c9068ff3} /*Display Adapter CPL Extension*/deskadp.dll = deskadp.dll
@{42071713-76d4-11d1-8b24-00a0c9068ff3} /*Display Monitor CPL Extension*/deskmon.dll = deskmon.dll
@{f92e8c40-3d33-11d2-b1aa-080036a75b03} /*Display TroubleShoot CPL Extension*/deskperf.dll = deskperf.dll
@{3EA48300-8CF6-101B-84FB-666CCB9BCD32} /*OLE Docfile Property Page*/docprop.dll = docprop.dll
@{11dbb47c-a525-400b-9e80-a54615a090c0} /*Execute Folder*/ExplorerFrame.dll = ExplorerFrame.dll
@{90b9bce2-b6db-4fd3-8451-35917ea1081b} /*Search Execute Command*/ExplorerFrame.dll = ExplorerFrame.dll
@{7988B573-EC89-11cf-9C00-00AA00A14F56} /*Disk Quota UI*/dskquoui.dll = dskquoui.dll
@{BD84B380-8CA2-1069-AB1D-08000948F534} /*Microsoft Windows Font Folder*/%SystemRoot%\system32\fontext.dll = %SystemRoot%\system32\fontext.dll
@{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E} /*Microsoft Windows Font File Icon Handler*/fontext.dll = fontext.dll
@{1a184871-359e-4f67-aad9-5b9905d62232} /*Microsoft Windows Font File Context Menu Handler*/fontext.dll = fontext.dll
@{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01} /*Microsoft Windows Font Previewer*/fontext.dll = fontext.dll
@{63da6ec0-2e98-11cf-8d82-444553540000} /*FTP Folders Webview*/%SystemRoot%\system32\msieftp.dll = %SystemRoot%\system32\msieftp.dll
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Compressed (zipped) Folder*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af} /*Compressed (zipped) Folder Context Menu*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{ed9d80b9-d157-457b-9192-0e7280313bf0} /*Compressed (zipped) Folder Drop Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{911051fa-c21c-4246-b470-070cd8df6dc4} /*.cab or .zip files*/(null) =
@{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} /*.CAB file viewer*/cabview.dll = cabview.dll
@{59be4990-f85c-11ce-aff7-00aa003ca9f6} /*Shell extensions for Microsoft Windows Network objects*/ntlanui2.dll = ntlanui2.dll
@{da67b8ad-e81b-4c70-9b91b417b5e33527} /*Windows Search Shell Service*/(null) =
@{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} /*DfsShell.DfsShell Property Sheet*/DfsShlEx.dll = DfsShlEx.dll
@{a38b883c-1682-497e-97b0-0a3a9e801682} /*IPropertyStore Handler for Images*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{C7657C4A-9F68-40fa-A4DF-96BC08EB3551} /*Photo Thumbnail Provider*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{3F30C968-480A-4C6C-862D-EFC0897BB84B} /*Photo Thumbnail Extractor*/C:\Windows\system32\PhotoMetadataHandler.dll = C:\Windows\system32\PhotoMetadataHandler.dll
@{BC65FB43-1958-4349-971A-210290480130} /*Network Explorer Property Sheet Handler*/%SystemRoot%\System32\NcdProp.dll = %SystemRoot%\System32\NcdProp.dll
@{d3e34b21-9d75-101a-8c3d-00aa001a1652} /*Bitmap Image*/(null) =
@{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} /*Video Media Properties Handler*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{E598560B-28D5-46aa-A14A-8A3BEA34B576} /*Windows Photo Gallery Viewer Video Verbs*/%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/
@{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3} /*Microsoft.ScannersAndCameras*/(null) =
@{0a4286ea-e355-44fb-8086-af3df7645bd9} /*Windows Media Player*/C:\PROGRA~1\WI4EB4~1\wmpband.dll = C:\PROGRA~1\WI4EB4~1\wmpband.dll
@{BB6B2374-3D79-41DB-87F4-896C91846510} /*EMDFileProperties*/emdmgmt.dll = emdmgmt.dll
@{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} /*Audio Media Properties Handler*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{E95A4861-D57A-4be1-AD0F-35267E261739} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{89D83576-6BD1-4c86-9454-BEB04E94C819} /*MAPI Search Namespace Extension*/%systemroot%\system32\mssvp.dll = %systemroot%\system32\mssvp.dll
@{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} /*Offline Files Folder*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{7A0F6AB7-ED84-46B6-B47E-02AA159A152B} /*Sync Center Simple Conflict Presenter*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{9D687A4C-1404-41ef-A089-883B6FBECDE6} /*Windows Photo Gallery Viewer Autoplay Handler*/(null) =
@{BE122A0E-4503-11DA-8BDE-F66BAD1E3F3A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{60fd46de-f830-4894-a628-6fa81bc0190d} /*DropTarget Object for Photo Printing Wizard*/%SystemRoot%\system32\photowiz.dll = %SystemRoot%\system32\photowiz.dll
@{37efd44d-ef8d-41b1-940d-96973a50e9e0} /*Windows Sidebar Properties*/(null) =
@{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\system32\audiodev.dll = %SystemRoot%\system32\audiodev.dll
@{00f20eb5-8fd6-4d9d-b75e-36801766c8f1} /*PhotoAcqDropTarget*/%ProgramFiles%\Windows Photo Gallery\PhotoAcq.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoAcq.dll /*file not found*/
@{BC48B32F-5910-47F5-8570-5074A8A5636A} /*Sync Results Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{ED228FDF-9EA8-4870-83B1-96B02CFE0D52} /*Games Folder*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{4E77131D-3629-431c-9818-C5679DC83E81} /*Offline Files Icon Overlay Handler*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{E413D040-6788-4C22-957E-175D1C513A34} /*Sync Center Conflict Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{67718415-c450-4f3c-bf8a-b487642dc39b} /*Windows Features*/(null) =
@{335a31dd-f04b-4d76-a925-d6b47cf360df} /**/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{91ADC906-6722-4B05-A12B-471ADDCCE132} /*Touch Band*/%SystemRoot%\System32\TouchX.dll = %SystemRoot%\System32\TouchX.dll
@{7D4734E6-047E-41e2-AEAA-E763B4739DC4} /*Windows Media Player Play as Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{2781761E-28E0-4109-99FE-B9D127C57AFE} /*Windows Defender IOfficeAntiVirus implementation*/%ProgramFiles%\Windows Defender\MpOav.dll /*file not found*/ = %ProgramFiles%\Windows Defender\MpOav.dll /*file not found*/
@{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A} /*Windows Photo Gallery Viewer Image Verbs*/%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/ = %ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll /*file not found*/
@{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Play as Playlist Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{4B534112-3AF6-4697-A77C-D62CE9B9E7CF} /*Sync Center Event Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C} /*Sync Setup Delegate Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} /*Offline Files Context Menu*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{85BBD920-42A0-1069-A2E4-08002B30309D} /*Briefcase*/syncui.dll = syncui.dll
@{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A} /*GameUX.RichGameMediaThumbnail*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{7EFA68C6-086B-43e1-A2D2-55A113531240} /*Offline Files Property Sheet Extension*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{d8559eb9-20c0-410e-beda-7ed416aecc2a} /*Windows Defender*/(null) =
@{576C9E85-1300-4EF5-BF6B-D00509F4EDCD} /*Sync Center Handler Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{5ea4f148-308c-46d7-98a9-49041b1dd468} /*Mobility Center Control Panel*/(null) =
@{289978AC-A101-4341-A817-21EBA7FD046D} /*Sync Center Conflict Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{877ca5ac-cb41-4842-9c69-9136e42d47e2} /*File Backup Index*/%systemroot%\system32\sdshext.dll = %systemroot%\system32\sdshext.dll
@{71D99464-3B6B-475C-B241-E15883207529} /*Sync Results Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{10CFC467-4392-11d2-8DB4-00C04FA31A66} /*Offline Files Folder Options*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{B32D3949-ED98-4DBB-B347-17A144969BBA} /*Sync Center Item Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Burn Audio CD Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{2E9E59C0-B437-4981-A647-9C34B9B90891} /*Sync Setup Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{58E3C745-D971-4081-9034-86E34B30836A} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} /*Sync Center Folder*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1} /*Welcome Center*/oobefldr.dll = oobefldr.dll
@{15D633E2-AD00-465b-9EC7-F56B7CDF8E27} /*Tablet PC Input Panel*/%CommonProgramFiles%\microsoft shared\ink\TipBand.dll /*file not found*/ = %CommonProgramFiles%\microsoft shared\ink\TipBand.dll /*file not found*/
@{78F3955E-3B90-4184-BD14-5397C15F1EFC} /**/%SystemRoot%\System32\shdocvw.dll = %SystemRoot%\System32\shdocvw.dll
@{F04CC277-03A2-4277-96A9-77967471BDFF} /*Sync Center Conflict Properties Extension*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{53BEDF0B-4E5B-4183-8DC9-B844344FA104} /*Microsoft Windows MAPI Preview Handler*/%SystemRoot%\system32\mssvp.dll = %SystemRoot%\system32\mssvp.dll
@{6b9228da-9c15-419e-856c-19e768a13bdc} /*Windows gadget DropTarget*/%ProgramFiles%\Windows Sidebar\sbdrop.dll /*file not found*/ = %ProgramFiles%\Windows Sidebar\sbdrop.dll /*file not found*/
@{8E25992B-373E-486E-80E5-BD23AE417E66} /*Sync Center Device Notification Sink*/%SystemRoot%\System32\SyncCenter.dll = %SystemRoot%\System32\SyncCenter.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{031EE060-67BC-460d-8847-E4A7C5E45A27} /*Windows Media Player Rich Preview Handler*/(null) =
@{1FA9085F-25A2-489B-85D4-86326EEDCD87} /*Manage Wireless Networks*/%SystemRoot%\system32\wlanpref.dll = %SystemRoot%\system32\wlanpref.dll
@{7dda204b-2097-47c9-8323-c40bb840ae44} /*XPS document*/(null) =
@{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60} /*RichGameMediaPropertyStore Class*/C:\Windows\System32\gameux.dll = C:\Windows\System32\gameux.dll
@{BD7A2E7B-21CB-41b2-A086-B309680C6B7E} /*Client Side Cache Namespace Extension*/%systemroot%\system32\mssvp.dll = %systemroot%\system32\mssvp.dll
@{8A734961-C4AA-4741-AC1E-791ACEBF5B39} /*Windows Media Player Shop Music Context Menu Handler*/%SystemRoot%\system32\wmpshell.dll = %SystemRoot%\system32\wmpshell.dll
@{7A9D77BD-5403-11d2-8785-2E0420524153} /*User Accounts*/(null) =
@{c5a40261-cd64-4ccf-84cb-c394da41d590} /*Video Thumbnail Extractor*/%SystemRoot%\System32\mediametadatahandler.dll = %SystemRoot%\System32\mediametadatahandler.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\Windows\system32\nvcpl.dll = C:\Windows\system32\nvcpl.dll
@{ED58A35B-B554-42AF-A26C-6F3D424200D3} /*Sony Power Management Extensiond*/C:\Program Files\Sony\VAIO Power Management\SPMPanel.dll = C:\Program Files\Sony\VAIO Power Management\SPMPanel.dll
@{9AFDE8D6-200C-4b41-A5FC-B7251DFD1A8E} /*Safearchive ContextMenu Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{055EF591-5C38-49a0-9BDA-51B1D69D0BF4} /*Safearchive ShellFolder Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{66C99756-1C92-4d3e-BA69-9400A6F731F5} /*Safearchive PropertySheetHandler Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{E6D7D89A-2232-446d-8A0F-D0F9B06DB1CA} /*Safearchive ExtractIcon Class*/C:\Program Files\Protector Suite QL\farchns.dll = C:\Program Files\Protector Suite QL\farchns.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL = C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
@{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B} /*Bluetooth*/C:\Windows\system32\TosBtExt.dll = C:\Windows\system32\TosBtExt.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/(null) =
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/(null) =
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/(null) =
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll = C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll
@{0563DB41-F538-4B37-A92D-4659049B7766} /*WLMD Message Handler*/C:\Program Files\Windows Live\Mail\mailcomm.dll = C:\Program Files\Windows Live\Mail\mailcomm.dll
@{06A2568A-CED6-4187-BB20-400B8C02BE5A} /**/(null) =
@{00F33137-EE26-412F-8D71-F84E4C2C6625} /**/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} /*Windows Live Photo Gallery Autoplay Drop Target*/(null) =
@{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} /*Windows Live Photo Gallery Viewer Drop Target*/(null) =
@{00F374B7-B390-4884-B372-2FC349F2172B} /*Windows Live Photo Gallery Editor Drop Target*/(null) =
@{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} /*Windows Live Photo Gallery Viewer Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} /*Windows Live Photo Gallery Editor Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00F30F90-3E96-453B-AFCD-D71989ECC2C7} /*Windows Live Photo Gallery Autoplay Drop Target Shim*/C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\Windows\system32\nvcpl.dll = C:\Windows\system32\nvcpl.dll
@{A155339D-CCCD-4714-85EB-3754B804C9DF} /*a-squared Free Shell Extension*/C:\Program Files\a-squared Free\a2freecontmenu.dll = C:\Program Files\a-squared Free\a2freecontmenu.dll
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{45C6AFA5-2C13-402f-BC5D-45CC8172EF6B} /*Bluetooth*/ = C:\Windows\system32\TosBtExt.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
BriefcaseMenu@{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\shell32.dll
Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
tosBtShllExt@{6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1} = C:\Windows\system32\TosBtShell.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = %SystemRoot%\system32\shell32.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
Offline Files@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} = %SystemRoot%\System32\cscui.dll
Photo! 3D ScreenSaver@{AA7A03E6-7FA5-42E7-9D7A-9A2A4E344B3F} =
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
tosBtShllExt@{6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1} = C:\Windows\system32\TosBtShell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{596AB062-B4D2-4215-9F74-E9109B0A8153} = %SystemRoot%\system32\twext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
a-squared Free Shell Extension@{A155339D-CCCD-4714-85EB-3754B804C9DF} = C:\Program Files\a-squared Free\a2freecontmenu.dll
BriefcaseMenu@{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
Offline Files@{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} = %SystemRoot%\System32\cscui.dll
Shell Extension for Malware scanning@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/ = C:\Program Files\AVG\AVG8\avgssie.dll /*file not found*/
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}c:\program files\google\googletoolbar1.dll = c:\program files\google\googletoolbar1.dll
@{CA6319C0-31B7-401E-A518-A07C3DB8F777}C:\PROGRA~1\GOOGLE~1\BAE.dll = C:\PROGRA~1\GOOGLE~1\BAE.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://it.yahoo.com = http://it.yahoo.com
@Start Pagehttp://home.sweetim.com = http://home.sweetim.com
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.comodo.com/search/ = http://www.comodo.com/search/
@Local PageC:\Windows\system32\blank.htm = C:\Windows\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
application/octet-stream@CLSID = mscoree.dll
application/x-complus@CLSID = mscoree.dll
application/x-msdownload@CLSID = mscoree.dll
deflate@CLSID = C:\Windows\system32\urlmon.dll
gzip@CLSID = C:\Windows\system32\urlmon.dll
text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
about@CLSID = C:\Windows\system32\mshtml.dll
cdl@CLSID = C:\Windows\system32\urlmon.dll
dvd@CLSID = C:\Windows\System32\msvidctl.dll
file@CLSID = C:\Windows\system32\urlmon.dll
ftp@CLSID = C:\Windows\system32\urlmon.dll
http@CLSID = C:\Windows\system32\urlmon.dll
https@CLSID = C:\Windows\system32\urlmon.dll
its@CLSID = %SystemRoot%\System32\itss.dll
javascript@CLSID = C:\Windows\system32\mshtml.dll
livecall@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
local@CLSID = C:\Windows\system32\urlmon.dll
mailto@CLSID = C:\Windows\system32\mshtml.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
mk@CLSID = C:\Windows\system32\urlmon.dll
ms-its@CLSID = %SystemRoot%\System32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
res@CLSID = C:\Windows\system32\mshtml.dll
tv@CLSID = C:\Windows\System32\msvidctl.dll
vbscript@CLSID = C:\Windows\system32\mshtml.dll
wlmailhtml@CLSID = C:\Program Files\Windows Live\Mail\mailcomm.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6AE2AC5C-D545-44E9-928B-693253A07B39} /*Connessione alla rete locale (LAN)*/ >>>
@IPAddress =
@NameServer =
@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
000000000001@LibraryPath = %SystemRoot%\system32\NLAapi.dll
000000000002@LibraryPath = %SystemRoot%\system32\napinsp.dll
000000000003@LibraryPath = %SystemRoot%\system32\pnrpnsp.dll
000000000004@LibraryPath = %SystemRoot%\system32\pnrpnsp.dll
000000000005@LibraryPath = %SystemRoot%\System32\mswsock.dll
000000000006@LibraryPath = %SystemRoot%\System32\winrnr.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000004@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000005@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000018@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000019@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000020@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000021@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000022@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000023@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000024@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000025@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000026@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000027@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000028@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup = Bluetooth Manager.lnk
---- EOF - GMER 1.0.14 ----
|
|
|
|
|
|
#154 |
|
Senior Member
Iscritto dal: Feb 2007
Città: Roma
Messaggi: 2155
|
Mi pare che GMER non abbia rilevato infezioni. Attendi comunque il parere di qualcun altro o effettua scansioni antirootkit con altri software ad es. AVIRA Rootkit Detection.
|
|
|
|
|
|
#155 |
|
Moderatore
Iscritto dal: Jun 2007
Città: 127.0.0.1
Messaggi: 25885
|
zairon
Il log pare pulito, sarebbe più fruibile se allegato su uno dei seguenti server http://fileqube.com/ o http://www.mediafire.com/index.php
Ciao
__________________
Try again and you will be luckier.
|
|
|
|
|
|
#156 |
|
Junior Member
Iscritto dal: Jul 2008
Messaggi: 9
|
scusate
avevo fatto la scanzione da utente, da amministratore gmer sotto la voce rootkit non mi ha trovato niente qui c'è il link dell' autostart , prima avevo fatto anche una scanzione con f secure internet 2008 ma non mi ha trovato niente grazie per la disponibilità e scusate ancora
|
|
|
|
|
|
#157 |
|
Junior Member
Iscritto dal: Jul 2008
Messaggi: 9
|
mi ero dimenticato il link
|
|
|
|
|
|
#158 |
|
Junior Member
Iscritto dal: Sep 2008
Messaggi: 7
|
petreste dare un'occhiata a questo log?
nn ci sono voci in rosso ma vorrei un'analisi più sicura.. grazie mille http://www.fileqube.com/shared/NONut95993 |
|
|
|
|
|
#159 |
|
Senior Member
Iscritto dal: Mar 2006
Messaggi: 608
|
Ciao a tutti !! Ho un problema con il pc...ogni tanto si blocca, poi riprende a funzionare, poi si blocca, poi riprende...etc, etc!!!
Antivir e Spyware Terminator non mi hanno trovato nulla, A-Squared si blocca prima che finisca la scansione. Ho fatto analizzare log di Hijack ma non ha trovato nulla di rilevante. Stò facendo scansione on-line con F-Secure. Ora vi posto il log di Gmer... Codice:
GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2008-09-20 12:46:06 Windows 5.1.2600 Service Pack 3 ---- User code sections - GMER 1.0.14 ---- .text C:\WINDOWS\Explorer.EXE[324] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\Explorer.EXE[324] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[324] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] USER32.DLL!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Administrator\Desktop\gmer.exe[800] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\winlogon.exe[984] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\winlogon.exe[984] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\services.exe[1032] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[1032] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\lsass.exe[1044] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[1044] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\svchost.exe[1204] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1204] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\svchost.exe[1268] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\Programmi\Windows Defender\MsMpEng.exe[1300] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\svchost.exe[1480] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1480] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\svchost.exe[1508] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1508] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] ntdll.dll!NtClose 7C91CFD0 5 Bytes JMP 10005060 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 10004F90 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!EndTask 7E3DA0A5 5 Bytes JMP 10004C30 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!mouse_event 7E3E673F 5 Bytes JMP 100016D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] USER32.dll!keybd_event 7E3E6783 5 Bytes JMP 10001550 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!BitBlt 77E46F79 5 Bytes JMP 10001860 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCA 77E4B7C2 5 Bytes JMP 10001230 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCW 77E4BE28 2 Bytes JMP 100013C0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] GDI32.dll!CreateDCW + 3 77E4BE2B 2 Bytes [ 1B, 98 ] .text C:\WINDOWS\system32\svchost.exe[1632] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 10004960 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1632] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 10004AD0 C:\WINDOWS\system32\guard32.dll ---- Kernel IAT/EAT - GMER 1.0.14 ---- IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F7202950] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F7202990] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F7202710] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F7202770] inspect.sys (COMODO Firewall Pro Firewall Driver/COMODO) ---- Devices - GMER 1.0.14 ---- AttachedDevice \FileSystem\Ntfs \Ntfs InCDRec.sys (Nero InCD File System Recognizer/Nero AG) AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO) AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO) AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO) AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO) AttachedDevice \FileSystem\Fastfat \Fat InCDRec.sys (Nero InCD File System Recognizer/Nero AG) ---- Registry - GMER 1.0.14 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0003c935273f Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0003c935273f@001370dd26fa 0x4B 0x43 0x40 0xA9 ... Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0003c935273f Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0003c935273f@001370dd26fa 0x4B 0x43 0x40 0xA9 ... ---- EOF - GMER 1.0.14 ---- |
|
|
|
|
|
#160 |
|
Senior Member
Iscritto dal: Feb 2004
Città: ♪ ♫ un giorno all'improvviso... ♪ ♫
Messaggi: 5716
|
Ciao amisci, mi date una mnao con il seguente log ???
Grazie anticipatamente Codice:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-24 18:17:44
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAllocateVirtualMemory [0xB6818960]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAssignProcessToJobObject [0xB6818D90]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwConnectPort [0xB6818280]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateFile [0xB681A290]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateKey [0xB681AE30]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreatePort [0xB6818140]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcess [0xB6818EC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcessEx [0xB6816CD0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateSection [0xB68168D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateThread [0xB6817280]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDebugActiveProcess [0xB6817B10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDeleteFile [0xB681A8F0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDeleteKey [0xB6819D10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDeleteValueKey [0xB681B6A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwEnumerateKey [0xB681A270]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwEnumerateValueKey [0xB681A280]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadDriver [0xB68187D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadKey [0xB681BA10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenFile [0xB681A650]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenKey [0xB6819EC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenProcess [0xB6816FE0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenSection [0xB6816B00]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenThread [0xB6817660]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwProtectVirtualMemory [0xB6818AD0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueryKey [0xB681A250]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueryValueKey [0xB681A260]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwReplaceKey [0xB6819ED0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestWaitReplyPort [0xB68184D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRestoreKey [0xB681A090]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwResumeThread [0xB6817EC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSaveKey [0xB681A240]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetContextThread [0xB68179C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetInformationFile [0xB681AB50]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetValueKey [0xB681B190]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwShutdownSystem [0xB6818710]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendProcess [0xB6818000]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendThread [0xB6817D60]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSystemDebugControl [0xB6817C40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateProcess [0xB6817130]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateThread [0xB6817850]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwWriteVirtualMemory [0xB6818C30]
INT 0x62 ? 89B9EBF8
INT 0x63 ? 899E9BF8
INT 0x63 ? 899E9BF8
INT 0x63 ? 899E9BF8
INT 0x83 ? 89B9EBF8
INT 0x83 ? 89B9EBF8
INT 0x83 ? 899E9BF8
INT 0x83 ? 899E9BF8
INT 0x83 ? 89B9EBF8
---- Kernel code sections - GMER 1.0.14 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C7C 80504508 12 Bytes [ 40, 81, 81, B6, C0, 8E, 81, ... ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2FB8 80504844 12 Bytes [ 00, 80, 81, B6, 60, 7D, 81, ... ]
? spcu.sys Impossibile trovare il file specificato. !
.text USBPORT.SYS!DllUnload B9C908AC 5 Bytes JMP 899E91D8
.text axrb2mo2.SYS B935B386 35 Bytes [ 00, 00, 00, 00, 00, 00, 20, ... ]
.text axrb2mo2.SYS B935B3AA 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text axrb2mo2.SYS B935B3C4 3 Bytes [ 00, 70, 02 ]
.text axrb2mo2.SYS B935B3C9 1 Byte [ 2E ]
.text axrb2mo2.SYS B935B3CB 9 Bytes [ 00, 00, 5A, 02, 00, 00, 00, ... ]
.text ...
? C:\WINDOWS\system32\drivers\OAnet.sys Accesso negato.
? C:\WINDOWS\system32\drivers\OAmon.sys Accesso negato.
? C:\WINDOWS\system32\drivers\OADriver.sys Accesso negato.
? C:\WINDOWS\TEMP\mc21.tmp Impossibile trovare il file specificato. !
---- User code sections - GMER 1.0.14 ----
.text C:\Programmi\a-squared Free\a2service.exe[1192] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exe[1476] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\SearchIndexer.exe[1636] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\SearchIndexer.exe[1636] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Programmi\Eset\nod32krn.exe[1676] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\nvsvc32.exe[1756] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[1780] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\svchost.exe[1928] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Online Armor\oaui.exe[2596] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\Programmi\Eset\nod32kui.exe[2696] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Eset\nod32kui.exe[2696] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\Programmi\Mozilla Firefox\firefox.exe[2804] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Mozilla Firefox\firefox.exe[2804] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2916] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2916] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe[2996] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3036] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\ctfmon.exe[3036] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.exe[3136] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\Programmi\OpenOffice.org 2.4\program\soffice.BIN[3188] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text E:\FIREFOX DOWNLOADS\8 - gmer.exe[3200] user32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\rundll32.exe[3788] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, 7F, E2 ]
.text C:\WINDOWS\system32\rundll32.exe[3788] USER32.dll!ExitWindowsEx 7E3DA275 6 Bytes JMP 5F0D0F5A
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A9040] spcu.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A913C] spcu.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A90BE] spcu.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A97FC] spcu.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A96D2] spcu.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6B9048] spcu.sys
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfAcquireSpinLock] C0840CEC
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_UCHAR] 053C0D74
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KeGetCurrentIrql] 57B80974
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfRaiseIrql] 8B000000
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfLowerIrql] 56C35DE5
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!HalGetInterruptVector] 8D08758B
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!HalTranslateBusAddress] 8D51FC4D
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KeStallExecutionProcessor] 8D52FD55
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!KfReleaseSpinLock] 8D51FE4D
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 8D52FF55
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!READ_PORT_USHORT] 8D51F84D
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 5052F455
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[HAL.dll!WRITE_PORT_UCHAR] EACAE856
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[WMILIB.SYS!WmiSystemControl] 0FC08520
IAT \SystemRoot\System32\Drivers\axrb2mo2.SYS[WMILIB.SYS!WmiCompleteRequest] 0001B185
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [BA99B720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [BA99B760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [BA99B410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [BA99B470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 89B9D1F8
AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )
Device \Driver\Tcpip \Device\Ip OAmon.sys
Device \Driver\usbohci \Device\USBPDO-0 899E71F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89C101F8
Device \Driver\dmio \Device\DmControl\DmConfig 89C101F8
Device \Driver\dmio \Device\DmControl\DmPnP 89C101F8
Device \Driver\dmio \Device\DmControl\DmInfo 89C101F8
Device \Driver\usbehci \Device\USBPDO-1 899D31F8
Device \Driver\usbohci \Device\USBPDO-2 899E71F8
Device \Driver\usbehci \Device\USBPDO-3 899D31F8
Device \Driver\Tcpip \Device\Tcp OAmon.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 89B9F1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 89B9F1F8
Device \Driver\Cdrom \Device\CdRom0 899901F8
Device \Driver\Cdrom \Device\CdRom1 899901F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{9A69858B-9555-4863-82DB-C726B1D67EB5} 89884500
Device \Driver\NetBT \Device\NetBt_Wins_Export 89884500
Device \Driver\PCI_PNP5288 \Device\0000004c spcu.sys
Device \Driver\sptd \Device\2297184038 spcu.sys
Device \Driver\Tcpip \Device\Udp OAmon.sys
Device \Driver\Tcpip \Device\RawIp OAmon.sys
Device \Driver\usbohci \Device\USBFDO-0 899E71F8
Device \Driver\usbehci \Device\USBFDO-1 899D31F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8828A1F8
Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys
Device \Driver\usbohci \Device\USBFDO-2 899E71F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{8BBCD01E-87B9-4F65-9932-7DDAF8D14EF5} 89884500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8828A1F8
Device \Driver\usbehci \Device\USBFDO-3 899D31F8
Device \Driver\Ftdisk \Device\FtControl 89B9F1F8
Device \Driver\axrb2mo2 \Device\Scsi\axrb2mo21Port4Path0Target0Lun0 898651F8
Device \Driver\axrb2mo2 \Device\Scsi\axrb2mo21 898651F8
Device \FileSystem\Cdfs \Cdfs 886AE500
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x52 0x40 0x14 0x4E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x10 0xA4 0xCD 0x94 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3A 0x7D 0xEF 0x5B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmi\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x52 0x40 0x14 0x4E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x10 0xA4 0xCD 0x94 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3A 0x7D 0xEF 0x5B ...
---- EOF - GMER 1.0.14 ----
|
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 15:32.




















