Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0006B160 | 14_2_0006B160 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00061180 | 14_2_00061180 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00065980 | 14_2_00065980 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00066B60 | 14_2_00066B60 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0007B420 | 14_2_0007B420 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00071820 | 14_2_00071820 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00068440 | 14_2_00068440 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0006A480 | 14_2_0006A480 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000754B0 | 14_2_000754B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00062CCC | 14_2_00062CCC |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00068CD0 | 14_2_00068CD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000788E0 | 14_2_000788E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000768F0 | 14_2_000768F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0006C960 | 14_2_0006C960 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0006BD80 | 14_2_0006BD80 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0007D190 | 14_2_0007D190 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000649E0 | 14_2_000649E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00077650 | 14_2_00077650 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00066660 | 14_2_00066660 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00070660 | 14_2_00070660 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00071270 | 14_2_00071270 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000782C0 | 14_2_000782C0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000756E0 | 14_2_000756E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00070EF0 | 14_2_00070EF0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0007C2F0 | 14_2_0007C2F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0007AB10 | 14_2_0007AB10 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00061B50 | 14_2_00061B50 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_0006E760 | 14_2_0006E760 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00064370 | 14_2_00064370 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_00072FD0 | 14_2_00072FD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000737D0 | 14_2_000737D0 |
Source: C:\Windows\System32\svchost.exe | Code function: 14_2_000727E0 | 14_2_000727E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0007B420 | 18_2_0007B420 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000768F0 | 18_2_000768F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0006B160 | 18_2_0006B160 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0006C960 | 18_2_0006C960 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0006BD80 | 18_2_0006BD80 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00061180 | 18_2_00061180 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00065980 | 18_2_00065980 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00070660 | 18_2_00070660 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000782C0 | 18_2_000782C0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0007C2F0 | 18_2_0007C2F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0007AB10 | 18_2_0007AB10 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00061B50 | 18_2_00061B50 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00066B60 | 18_2_00066B60 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00071820 | 18_2_00071820 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00068440 | 18_2_00068440 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0006A480 | 18_2_0006A480 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000754B0 | 18_2_000754B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00062CCC | 18_2_00062CCC |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00068CD0 | 18_2_00068CD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000788E0 | 18_2_000788E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0007D190 | 18_2_0007D190 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000649E0 | 18_2_000649E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00077650 | 18_2_00077650 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00066660 | 18_2_00066660 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00071270 | 18_2_00071270 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000756E0 | 18_2_000756E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00070EF0 | 18_2_00070EF0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_0006E760 | 18_2_0006E760 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00064370 | 18_2_00064370 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000737D0 | 18_2_000737D0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_00072FD0 | 18_2_00072FD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 18_2_000727E0 | 18_2_000727E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0006B160 | 21_2_0006B160 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00061180 | 21_2_00061180 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00065980 | 21_2_00065980 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0007C2F0 | 21_2_0007C2F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0007B420 | 21_2_0007B420 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00071820 | 21_2_00071820 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00068440 | 21_2_00068440 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0006A480 | 21_2_0006A480 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000754B0 | 21_2_000754B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00062CCC | 21_2_00062CCC |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00068CD0 | 21_2_00068CD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000788E0 | 21_2_000788E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000768F0 | 21_2_000768F0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0006C960 | 21_2_0006C960 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0006BD80 | 21_2_0006BD80 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0007D190 | 21_2_0007D190 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000649E0 | 21_2_000649E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00077650 | 21_2_00077650 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00066660 | 21_2_00066660 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00070660 | 21_2_00070660 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00071270 | 21_2_00071270 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000782C0 | 21_2_000782C0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000756E0 | 21_2_000756E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00070EF0 | 21_2_00070EF0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0007AB10 | 21_2_0007AB10 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00061B50 | 21_2_00061B50 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00066B60 | 21_2_00066B60 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_0006E760 | 21_2_0006E760 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00064370 | 21_2_00064370 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_00072FD0 | 21_2_00072FD0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000737D0 | 21_2_000737D0 |
Source: C:\Windows\System32\svchost.exe | Code function: 21_2_000727E0 | 21_2_000727E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018007C998 | 36_2_000000018007C998 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800949E0 | 36_2_00000001800949E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180096D20 | 36_2_0000000180096D20 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800796DC | 36_2_00000001800796DC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800B1758 | 36_2_00000001800B1758 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A7D24 | 36_2_00000001800A7D24 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800BA050 | 36_2_00000001800BA050 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800BA050 | 36_2_00000001800BA050 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018000E070 | 36_2_000000018000E070 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AA078 | 36_2_00000001800AA078 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C40FC | 36_2_00000001800C40FC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180030108 | 36_2_0000000180030108 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018001015C | 36_2_000000018001015C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800B6170 | 36_2_00000001800B6170 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018008E1F4 | 36_2_000000018008E1F4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180046218 | 36_2_0000000180046218 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AA254 | 36_2_00000001800AA254 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018001E278 | 36_2_000000018001E278 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AC324 | 36_2_00000001800AC324 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018003434C | 36_2_000000018003434C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C8368 | 36_2_00000001800C8368 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180058374 | 36_2_0000000180058374 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005A418 | 36_2_000000018005A418 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018003C420 | 36_2_000000018003C420 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018002A560 | 36_2_000000018002A560 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A4624 | 36_2_00000001800A4624 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800966D0 | 36_2_00000001800966D0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005C738 | 36_2_000000018005C738 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018008C76C | 36_2_000000018008C76C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018000C874 | 36_2_000000018000C874 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800928E8 | 36_2_00000001800928E8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018006A930 | 36_2_000000018006A930 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018006692C | 36_2_000000018006692C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180040948 | 36_2_0000000180040948 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800B4960 | 36_2_00000001800B4960 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180030980 | 36_2_0000000180030980 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180052990 | 36_2_0000000180052990 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800449D4 | 36_2_00000001800449D4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018004EA90 | 36_2_000000018004EA90 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180018AE0 | 36_2_0000000180018AE0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005CAE4 | 36_2_000000018005CAE4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180088AE4 | 36_2_0000000180088AE4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800CEB2C | 36_2_00000001800CEB2C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A8CA0 | 36_2_00000001800A8CA0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C2CB8 | 36_2_00000001800C2CB8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C8D04 | 36_2_00000001800C8D04 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180026D18 | 36_2_0000000180026D18 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180048ECC | 36_2_0000000180048ECC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180090F28 | 36_2_0000000180090F28 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018007CF40 | 36_2_000000018007CF40 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005AF68 | 36_2_000000018005AF68 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C8F7C | 36_2_00000001800C8F7C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018004CFAC | 36_2_000000018004CFAC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180050FF8 | 36_2_0000000180050FF8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018000100C | 36_2_000000018000100C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018008B09C | 36_2_000000018008B09C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018006B0A4 | 36_2_000000018006B0A4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800830B4 | 36_2_00000001800830B4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AB104 | 36_2_00000001800AB104 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180091180 | 36_2_0000000180091180 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018003D214 | 36_2_000000018003D214 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C3250 | 36_2_00000001800C3250 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018007F2B4 | 36_2_000000018007F2B4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800832C4 | 36_2_00000001800832C4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A32FC | 36_2_00000001800A32FC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180031367 | 36_2_0000000180031367 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180089370 | 36_2_0000000180089370 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AF3B8 | 36_2_00000001800AF3B8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018002F3E0 | 36_2_000000018002F3E0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018008D428 | 36_2_000000018008D428 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018007549C | 36_2_000000018007549C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800434B0 | 36_2_00000001800434B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005F504 | 36_2_000000018005F504 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A3504 | 36_2_00000001800A3504 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180095514 | 36_2_0000000180095514 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800235C4 | 36_2_00000001800235C4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018009B5EC | 36_2_000000018009B5EC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018004D628 | 36_2_000000018004D628 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800776A8 | 36_2_00000001800776A8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800896B0 | 36_2_00000001800896B0 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180057710 | 36_2_0000000180057710 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180093798 | 36_2_0000000180093798 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800597C4 | 36_2_00000001800597C4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800817D1 | 36_2_00000001800817D1 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018000F800 | 36_2_000000018000F800 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018006984C | 36_2_000000018006984C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180049878 | 36_2_0000000180049878 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800838B8 | 36_2_00000001800838B8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800C38FC | 36_2_00000001800C38FC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800918F4 | 36_2_00000001800918F4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180087920 | 36_2_0000000180087920 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180051948 | 36_2_0000000180051948 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800BF960 | 36_2_00000001800BF960 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800219C8 | 36_2_00000001800219C8 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800AF9D4 | 36_2_00000001800AF9D4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018006BA60 | 36_2_000000018006BA60 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800BDAEC | 36_2_00000001800BDAEC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180029B24 | 36_2_0000000180029B24 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800ABB78 | 36_2_00000001800ABB78 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180037B94 | 36_2_0000000180037B94 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800D3BFC | 36_2_00000001800D3BFC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180087C00 | 36_2_0000000180087C00 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180095BF4 | 36_2_0000000180095BF4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005BC74 | 36_2_000000018005BC74 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800A3C88 | 36_2_00000001800A3C88 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018004FCC4 | 36_2_000000018004FCC4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800ADD00 | 36_2_00000001800ADD00 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800CDCFC | 36_2_00000001800CDCFC |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018005FD20 | 36_2_000000018005FD20 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180045D38 | 36_2_0000000180045D38 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018003BE18 | 36_2_000000018003BE18 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180025E28 | 36_2_0000000180025E28 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180067E78 | 36_2_0000000180067E78 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_000000018000BEA4 | 36_2_000000018000BEA4 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180065F9C | 36_2_0000000180065F9C |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_0000000180087F98 | 36_2_0000000180087F98 |
Source: C:\Windows\System32\svchost.exe | Code function: 36_2_00000001800BFFBC | 36_2_00000001800BFFBC |
Source: C:\Windows\System32\svchost.exe | Code function: 39_2_0000000180001B4C | 39_2_0000000180001B4C |
Source: C:\Windows\System32\svchost.exe | Code function: 39_2_0000000180002720 | 39_2_0000000180002720 |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 xor edx, edx 0x0000000b div esi 0x0000000d mov ebx, edx 0x0000000f test ebp, ebp 0x00000011 je 2AA5968Ch 0x00000013 mov ecx, dword ptr [edi+ebx*4] 0x00000016 lea eax, dword ptr [ebp+01h] 0x00000019 test ecx, ecx 0x0000001b jne 2AA59327h 0x0000001d mov ebp, eax 0x0000001f call 2AA42696h 0x00000024 dec eax 0x00000025 sub esp, 28h 0x00000028 call dword ptr [0001BF96h] 0x0000002e jmp 2AA59350h 0x00000030 jmp dword ptr [0007C47Ah] 0x00000036 mov ecx, dword ptr [7FFE0004h] 0x0000003d dec eax 0x0000003e mov eax, dword ptr [7FFE0320h] 0x00000045 dec eax 0x00000046 imul eax, ecx 0x00000049 dec eax 0x0000004a shr eax, 18h 0x0000004d ret 0x0000004e mov ecx, eax 0x00000050 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F876h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA594F0h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59513h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59130h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4FB96h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59350h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4F9F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59150h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59490h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA594B3h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59150h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA596B5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FF96h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4FD36h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59193h 0x00000033 call 2AA4FF96h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59213h 0x00000031 call 2AA4FBF6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59193h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59813h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA598F0h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59653h 0x00000033 call 2AA4FB36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA598F0h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA594B3h 0x00000031 call 2AA4FEF6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59313h 0x00000033 call 2AA4F7F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA598B3h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59130h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FB96h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59490h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59524h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA591F5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F9F6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59490h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59653h 0x00000033 call 2AA4FBB6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA594E4h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59813h 0x00000031 call 2AA4FB96h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4F9F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59244h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59653h 0x00000031 call 2AA4FB36h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59490h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59130h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59124h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4FBF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59250h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59275h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59350h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59144h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59250h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA598B3h 0x00000031 call 2AA4FEF6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59350h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA594E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4FBF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA590F3h 0x00000031 call 2AA4FF96h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59130h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59490h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59113h 0x00000031 call 2AA4FD36h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA594B3h 0x00000031 call 2AA4FD36h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59350h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FB96h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59490h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59653h 0x00000031 call 2AA4FF96h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59530h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA594B5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FB36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA591D0h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4FB36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59575h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F7F6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59453h 0x00000031 call 2AA4F876h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59313h 0x00000033 call 2AA4FB36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA596B5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59350h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA590F3h 0x00000033 call 2AA4FF96h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA591D0h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59244h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4F8F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA594B5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59250h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4F8F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA598B3h 0x00000031 call 2AA4FBF6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59350h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4F9F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59490h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA596B5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F9F6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4F7D6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59144h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59313h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA594F0h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59915h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59813h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA598F0h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4F7F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA590F3h 0x00000031 call 2AA4FF96h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA591D0h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59244h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59213h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59490h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59193h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA591C4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA598B3h 0x00000033 call 2AA4FB36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59124h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4FEF6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59850h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59193h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59490h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59313h 0x00000033 call 2AA4F8F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59375h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F8F6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59250h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59313h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59550h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA594E4h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59653h 0x00000031 call 2AA4FB36h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA598F0h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4F7F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA591F5h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA591D0h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59844h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA594B3h 0x00000033 call 2AA4FBB6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59275h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59490h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4F9F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59130h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59155h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59350h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59124h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA590F3h 0x00000033 call 2AA4F7D6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59313h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59490h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59684h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59213h 0x00000033 call 2AA4F876h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59124h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4F8F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA594F0h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59344h 0x00000022 mov al, cl 0x00000024 lea ebp, dword ptr [eax+eax*2] 0x00000027 mov byte ptr [esi], bl 0x00000029 dec eax 0x0000002a inc esi 0x0000002c dec eax 0x0000002d cmp esi, edi 0x0000002f jc 2AA59813h 0x00000031 call 2AA4F9F6h 0x00000036 dec eax 0x00000037 sub esp, 28h 0x0000003a call dword ptr [0001BF96h] 0x00000040 jmp 2AA59690h 0x00000042 jmp dword ptr [0007C47Ah] 0x00000048 mov ecx, dword ptr [7FFE0004h] 0x0000004f dec eax 0x00000050 mov eax, dword ptr [7FFE0320h] 0x00000057 dec eax 0x00000058 imul eax, ecx 0x0000005b dec eax 0x0000005c shr eax, 18h 0x0000005f ret 0x00000060 mov ecx, eax 0x00000062 rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59244h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59453h 0x00000033 call 2AA4F9F6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59375h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FD36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA598F0h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59875h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FEF6h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59250h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA598E4h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59213h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59690h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59155h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4F876h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59850h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59484h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59193h 0x00000033 call 2AA4FEF6h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59850h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x00000061 ret 0x00000062 mov ecx, ea |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 sub edi, ebx 0x0000000b xor ebp, ebp 0x0000000d xor edx, edx 0x0000000f div edi 0x00000011 inc esp 0x00000012 mov esi, edx 0x00000014 inc esp 0x00000015 add esi, ebx 0x00000017 je 2AA59275h 0x00000019 dec edx 0x0000001a lea edi, dword ptr [esi+esi] 0x0000001d call 2AA4FB36h 0x00000022 dec eax 0x00000023 sub esp, 28h 0x00000026 call dword ptr [0001BF96h] 0x0000002c jmp 2AA59350h 0x0000002e jmp dword ptr [0007C47Ah] 0x00000034 mov ecx, dword ptr [7FFE0004h] 0x0000003b dec eax 0x0000003c mov eax, dword ptr [7FFE0320h] 0x00000043 dec eax 0x00000044 imul eax, ecx 0x00000047 dec eax 0x00000048 shr eax, 18h 0x0000004b ret 0x0000004c mov ecx, eax 0x0000004e rdtsc |
Source: C:\Windows\System32\svchost.exe | RDTSC instruction interceptor: First address: 6595c second address: 6595c instructions: 0x00000000 rdtsc 0x00000002 add eax, ecx 0x00000004 dec eax 0x00000005 add esp, 28h 0x00000008 ret 0x00000009 add ebp, 19h 0x0000000c xor edx, edx 0x0000000e div ebp 0x00000010 add dl, 00000061h 0x00000013 xor eax, eax 0x00000015 cmp dl, 0000007Bh 0x00000018 setl cl 0x0000001b mov bl, 20h 0x0000001d cmp dl, 0000007Ah 0x00000020 jnle 2AA59124h 0x00000022 mov ebx, edx 0x00000024 mov al, cl 0x00000026 lea ebp, dword ptr [eax+eax*2] 0x00000029 mov byte ptr [esi], bl 0x0000002b dec eax 0x0000002c inc esi 0x0000002e dec eax 0x0000002f cmp esi, edi 0x00000031 jc 2AA59813h 0x00000033 call 2AA4FD36h 0x00000038 dec eax 0x00000039 sub esp, 28h 0x0000003c call dword ptr [0001BF96h] 0x00000042 jmp 2AA59350h 0x00000044 jmp dword ptr [0007C47Ah] 0x0000004a mov ecx, dword ptr [7FFE0004h] 0x00000051 dec eax 0x00000052 mov eax, dword ptr [7FFE0320h] 0x00000059 dec eax 0x0000005a imul eax, ecx 0x0000005d dec eax 0x0000005e shr eax, 18h 0x |