GMER 1.0.12.12011 -
http://www.gmer.netRootkit scan 2007-01-20 19:04:02
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.12 ----
.text ntdll.dll!NtClose 7C90D586 5 Bytes JMP 72033FAA
.text ntdll.dll!NtCreateProcess 7C90D754 5 Bytes JMP 72034135
.text ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes JMP 72034019
.text ntdll.dll!NtCreateSection 7C90D793 5 Bytes JMP 72033FC8
---- User code sections - GMER 1.0.12 ----
.text C:\Programmer\MSN Messenger\msnmsgr.exe[1284] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 5 Bytes JMP 004E12D0 C:\Programmer\MSN Messenger\MsnMsgr.Exe
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NlsMbOemCodePageTag + FFF84FE8 7C901000 91 Bytes [ 8B, EC, 81, EC, 80, 02, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnterCriticalSection + 58 7C90105D 4 Bytes JMP 7C9013F7 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnterCriticalSection + 5E 7C901063 35 Bytes [ 39, 75, 10, 75, 0A, B8, F1, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnterCriticalSection + 83 7C901088 41 Bytes [ 68, 38, E7, 84, 7C, 8D, 85, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnterCriticalSection + AE 7C9010B3 19 Bytes [ 00, 8D, 85, C4, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnterCriticalSection + C2 7C9010C7 12 Bytes [ 50, 8D, 85, 98, FD, FF, FF, ... ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlLeaveCriticalSection + 10 7C9010FD 54 Bytes [ 89, B5, D4, FD, FF, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlTryEnterCriticalSection + 9 7C901134 1 Byte [ 05 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlTryEnterCriticalSection + C 7C901137 12 Bytes [ 80, 75, 02, 33, FF, 3B, FE, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlTryEnterCriticalSection + 19 7C901144 24 Bytes [ 8B, 85, 88, FD, FF, FF, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlTryEnterCriticalSection + 32 7C90115D 57 Bytes [ 10, 00, 00, 68, 00, 20, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!LdrInitializeThunk + 19 7C901197 4 Bytes [ 8D, 85, E8, FD ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!LdrInitializeThunk + 1E 7C90119C 26 Bytes [ FF, 50, 6A, FF, FF, D3, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlActivateActivationContextUnsafeFast + 2 7C9011B7 67 Bytes [ B5, 88, FD, FF, FF, 8D, 85, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + 1 7C9011FB 11 Bytes [ BD, D4, FD, FF, FF, 3B, FE, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlDeactivateActivationContextUnsafeFast + E 7C901208 126 Bytes CALL 0890120A
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInitString + 2B 7C901287 52 Bytes [ 8D, 85, DC, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInitAnsiString + 23 7C9012BC 78 Bytes [ FF, 73, 1B, 8B, 85, E4, FD, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInitUnicodeString + 35 7C90130B 1 Byte [ 04 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInitUnicodeString + 37 7C90130D 61 Bytes [ 48, 04, 6A, 0E, 6A, 08, 8D, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!cos + 20 7C90134B 66 Bytes [ 8D, 85, D4, FD, FF, FF, 50, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!cos + 63 7C90138E 63 Bytes [ FF, 6A, 14, 6A, 08, 8D, 85, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!log + 4 7C9013CE 109 Bytes CALL CD9013D0
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIlog + 6A 7C90143D 88 Bytes [ C7, 45, EC, 40, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIlog + C3 7C901496 8 Bytes [ 00, 00, C7, 45, F4, 40, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIlog + CC 7C90149F 22 Bytes [ 89, 4D, F0, FF, 15, 70, 12, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIpow 7C9014B7 88 Bytes [ 90, 90, 90, 8B, FF, 55, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIpow + 59 7C901510 59 Bytes [ 02, 00, 00, 8D, 85, FC, FD, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIpow + 95 7C90154C 261 Bytes CALL F190154E
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIpow + 19B 7C901652 69 Bytes [ 0D, 56, 89, 46, 5C, E8, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_CIpow + 1E1 7C901698 79 Bytes [ 01, 8B, 46, 0C, 8B, 40, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sin + 9 7C9016E8 31 Bytes [ C0, 75, 02, 33, FF, 39, 9D, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sin + 29 7C901708 57 Bytes [ FF, 15, 10, 10, 80, 7C, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sin + 63 7C901742 34 Bytes [ 70, 18, FF, D6, 39, 9D, E8, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sin + 86 7C901765 20 Bytes [ DC, FD, FF, FF, 8B, 4D, FC, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sin + 9E 7C90177D 139 Bytes [ 8B, FF, 55, 8B, EC, 51, 83, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!sqrt + 77 7C901809 244 Bytes [ 00, 00, F6, 45, 21, 01, 74, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alldvrm + 12 7C9018FE 72 Bytes JMP 3E53A405
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alldvrm + 5B 7C901947 23 Bytes [ 75, 0C, 66, 83, 27, 00, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alldvrm + 73 7C90195F 94 Bytes [ 45, 18, 85, C0, 74, 02, 89, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alldvrm + D2 7C9019BE 34 Bytes [ 80, 75, 12, 8B, 4D, 18, 85, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allmul + 11 7C9019E1 23 Bytes [ EC, 8B, 45, 0C, 53, 33, DB, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allmul + 29 7C9019F9 18 Bytes [ 7D, 08, FF, 75, 10, 8D, 70, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alloca_probe + 3 7C901A0C 30 Bytes [ 85, C0, 7C, 08, 3B, C6, 77, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_alloca_probe + 22 7C901A2B 64 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allrem + 21 7C901A6C 49 Bytes [ FF, 55, 8B, EC, 6A, 00, 6A, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allrem + 53 7C901A9E 7 Bytes [ 08, 00, 90, 90, 90, 90, 90 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allrem + 5B 7C901AA6 101 Bytes [ FF, 55, 8B, EC, FF, 75, 0C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_allshl + A 7C901B0C 62 Bytes [ 89, 56, 08, 74, 28, BF, 04, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_aulldiv 7C901B4C 58 Bytes [ 90, 90, 90, 6A, 44, 68, 08, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_aulldiv + 3B 7C901B87 193 Bytes [ 73, 89, 5D, E4, 89, 5D, FC, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_aulldvrm + 90 7C901C49 53 Bytes [ 04, 37, 50, FF, 15, 10, 15, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_aullrem + 2C 7C901C7F 115 Bytes [ 45, FC, 47, 47, 66, 83, 38, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!_ftol + 2 7C901CF3 132 Bytes [ 4D, F8, 89, 08, 8B, 4D, FC, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!atan + 3 7C901D78 12 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!atan + 10 7C901D85 329 Bytes [ 74, 2A, FF, 75, 0C, FF, 75, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!ceil + B1 7C901ECF 134 Bytes [ 00, 83, A5, B4, FA, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!ceil + 139 7C901F57 174 Bytes CALL 7C91E918 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!floor + A9 7C902006 7 Bytes [ 53, 00, 79, 00, 72, 00, 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!floor + B1 7C90200E 67 Bytes [ 73, 00, 6B, 00, 24, 00, 53, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!floor + F5 7C902052 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!floor + F7 7C902054 1 Byte [ 72 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!floor + F9 7C902056 3 Bytes [ 6E, 00, 65 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memchr + 17 7C9020BC 1 Byte [ 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memchr + 19 7C9020BE 15 Bytes [ 28, 00, 33, 00, 37, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memchr + 29 7C9020CE 1 Byte [ 72 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memchr + 2B 7C9020D0 157 Bytes [ 6F, 00, 29, 00, 29, 00, 2F, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcmp + 1F 7C90216E 87 Bytes [ 61, 00, 72, 00, 6B, 00, 2F, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcmp + 77 7C9021C6 1 Byte [ 49 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcmp + 79 7C9021C8 33 Bytes [ 43, 00, 20, 00, 2D, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcmp + 9B 7C9021EA 5 Bytes [ 67, 00, 65, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcmp + A1 7C9021F0 47 Bytes [ 28, 00, 32, 00, 30, 00, 32, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcpy + 20 7C902220 3 Bytes [ 20, 00, 28 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcpy + 24 7C902224 1 Byte [ 49 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcpy + 26 7C902226 27 Bytes [ 42, 00, 4D, 00, 20, 00, 45, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcpy + 42 7C902242 89 Bytes [ 61, 00, 6C, 00, 69, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memcpy + 9C 7C90229C 63 Bytes [ 4C, 00, 61, 00, 74, 00, 69, ... ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memmove + 20 7C90255A 3 Bytes [ 29, 00, 19 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memmove + 24 7C90255E 1 Byte [ 24 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memmove + 26 7C902560 27 Bytes [ 24, 00, 24, 00, 31, 00, 32, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memmove + 42 7C90257C 91 Bytes [ 2D, 00, 20, 00, 74, 00, 79, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!memmove + 9E 7C9025D8 62 Bytes [ 20, 00, 28, 00, 41, 00, 4E, ... ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcpy + B 7C9028E2 1 Byte [ 6B ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcpy + D 7C9028E4 17 Bytes [ 20, 00, 28, 00, 6E, 00, 79, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcat + A 7C9028F6 13 Bytes [ 29, 00, 24, 00, 4E, 00, 6F, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcat + 1A 7C902906 39 Bytes [ 1F, 00, 50, 00, 6F, 00, 72, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcat + 42 7C90292E 1 Byte [ 61 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcat + 44 7C902930 3 Bytes [ 6C, 00, 29 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcat + 48 7C902934 1 Byte [ 24 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcmp + D 7C9029DE 67 Bytes [ 69, 00, 20, 00, 28, 00, 6B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcmp + 53 7C902A24 17 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcmp + 65 7C902A36 1 Byte [ 4D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strcmp + 67 7C902A38 109 Bytes [ 61, 00, 6C, 00, 61, 00, 79, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strlen + 9 7C902AA6 13 Bytes [ 65, 00, 6B, 00, 69, 00, 73, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strlen + 17 7C902AB4 1 Byte [ 6B ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strlen + 19 7C902AB6 23 Bytes [ 79, 00, 72, 00, 69, 00, 6C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strlen + 31 7C902ACE 10 Bytes [ 62, 00, 65, 00, 6B, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strlen + 3C 7C902AD9 6 Bytes [ 00, 61, 00, 6E, 00, 00 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncat + B 7C902B26 1 Byte [ 70 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncat + D 7C902B28 8 Bytes [ 74, 00, 65, 00, 6E, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncat + 17 7C902B32 15 Bytes [ 3A, 00, 4B, 00, 69, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncat + 27 7C902B42 21 Bytes [ 6B, 00, 20, 00, 28, 00, 48, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncat + 3D 7C902B58 17 Bytes [ 20, 00, 53, 00, 2E, 00, 41, ... ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncpy + F 7C902C8F 6 Bytes [ 00, 00, 00, 16, 00, 46 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncpy + 16 7C902C96 26 Bytes [ 72, 00, 61, 00, 6E, 00, 73, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncpy + 31 7C902CB1 4 Bytes [ 00, 24, 00, 43 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncpy + 36 7C902CB6 39 Bytes [ 61, 00, 6E, 00, 61, 00, 64, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strncpy + 5E 7C902CDE 1 Byte [ 53 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strpbrk + 36 7C902DB9 126 Bytes [ 00, 73, 00, 74, 00, 72, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strspn + 4B 7C902E38 1 Byte [ 70 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!strspn + 4D 7C902E3A 18 Bytes [ 61, 00, 6E, 00, 73, 00, 6B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!tan + F 7C902E4D 40 Bytes [ 00, 65, 00, 6D, 00, 61, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!tan + 38 7C902E76 1 Byte [ 61 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!tan + 3A 7C902E78 39 Bytes [ 6E, 00, 73, 00, 6B, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!tan + 62 7C902EA0 6 Bytes [ 7A, 00, 00, 00, 00, 00 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!tan + 69 7C902EA7 6 Bytes [ 00, 00, 00, 1B, 00, 41 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInterlockedPushListSList + C 7C902F61 8 Bytes [ 00, 00, 00, 22, 00, 54, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInterlockedPushListSList + 15 7C902F6A 11 Bytes [ 73, 00, 6B, 00, 20, 00, 28, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlInterlockedPushListSList + 21 7C902F76 17 Bytes [ 65, 00, 63, 00, 68, 00, 74, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFirstEntrySList + 6 7C902F88 5 Bytes [ 69, 00, 6E, 00, 29 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFirstEntrySList + C 7C902F8E 27 Bytes [ 24, 00, 4C, 00, 69, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFirstEntrySList + 28 7C902FAA 19 Bytes [ 00, 00, 21, 00, 45, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlUshortByteSwap + A 7C902FBE 1 Byte [ 28 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlUshortByteSwap + C 7C902FC0 3 Bytes [ 4E, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlUshortByteSwap + 10 7C902FC4 13 Bytes [ 77, 00, 20, 00, 5A, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlUlongByteSwap + 9 7C902FD2 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlUlongByteSwap + B 7C902FD4 89 Bytes [ 64, 00, 29, 00, 24, 00, 4E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCompareMemory + 39 7C90302F 13 Bytes [ 8B, B5, C8, FD, FF, FF, 3B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCompareMemory + 47 7C90303D 8 Bytes [ 6A, 08, 59, 8D, 85, F8, FD, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCompareMemory + 50 7C903046 79 Bytes [ 50, 8D, 85, D8, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFillMemory + 16 7C903096 49 Bytes [ 53, FF, B5, F0, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFillMemory + 48 7C9030C8 30 Bytes [ 1F, 8D, 85, CC, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlFillMemory + 67 7C9030E7 94 Bytes [ 00, 8B, 35, 10, 10, 80, 7C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlZeroMemory + 2C 7C903147 54 Bytes [ 00, FF, B5, DC, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlMoveMemory + 2D 7C90317E 60 Bytes [ 00, 8B, F0, 3B, F3, 74, 1E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlMoveMemory + 6B 7C9031BC 25 Bytes [ 3B, C3, 89, 85, F8, FD, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlMoveMemory + 85 7C9031D6 39 Bytes [ 35, 10, 10, 80, 7C, 8D, 85, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlMoveMemory + AD 7C9031FE 174 Bytes [ 40, 30, 53, FF, 70, 18, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlMoveMemory + 15C 7C9032AD 93 Bytes [ 85, F8, FD, FF, FF, EB, 09, ... ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnlargedUnsignedMultiply + 1 7C9034F0 10 Bytes [ FF, 55, 8B, EC, 5D, E9, 32, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnlargedUnsignedMultiply + 10 7C9034FF 25 Bytes [ 8B, FF, 55, 8B, EC, 83, EC, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlEnlargedUnsignedDivide + 19 7C903519 117 Bytes [ 7D, F4, EB, 28, 8B, 03, 83, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlExtendedMagicDivide + 8 7C90358F 49 Bytes [ 4D, 0E, 8B, 55, 30, 66, 89, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlExtendedMagicDivide + 3A 7C9035C1 124 Bytes [ 0F, B7, 00, 8B, 55, 08, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlExtendedIntegerMultiply + 21 7C90363E 28 Bytes [ 8B, D0, 85, D2, 89, 55, F4, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlExtendedIntegerMultiply + 3E 7C90365B 48 Bytes [ 02, 02, 89, 08, 8D, 4C, 12, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlLargeIntegerShiftLeft + 11 7C90368C 28 Bytes [ 0C, 8A, 89, 08, 33, C9, 39, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlLargeIntegerShiftRight + 1 7C9036A9 15 Bytes [ 45, 28, EB, 03, 8A, 68, 02, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlLargeIntegerShiftRight + 11 7C9036B9 11 Bytes [ 4D, 18, C6, 40, 02, 02, EB, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlLargeIntegerShiftRight + 1D 7C9036C5 165 Bytes [ 75, 20, 83, CA, FF, 39, 11, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlConvertUlongToLargeInteger + 26 7C90376B 37 Bytes [ D2, F3, A6, 74, 05, 1B, D2, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlConvertUlongToLargeInteger + 4C 7C903791 2 Bytes JMP 7C903709 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlConvertUlongToLargeInteger + 4F 7C903794 106 Bytes [ FF, FF, 89, 11, EB, 02, 89, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlConvertUlongToLargeInteger + BA 7C9037FF 84 Bytes [ 68, 6C, 37, 88, 7C, E8, 49, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCaptureContext + F 7C903854 6 Bytes [ 75, 3E, 68, 19, 00, 02 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCaptureContext + 16 7C90385B 56 Bytes [ 68, B8, BF, 81, 7C, 68, 50, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCaptureContext + 4F 7C903894 36 Bytes [ 56, FF, 15, 7C, 11, 80, 7C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCaptureContext + 74 7C9038B9 101 Bytes [ 8D, 85, E0, FB, FF, FF, 89, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!RtlCaptureContext + DA 7C90391F 4 Bytes [ EC, 81, EC, 40 ]
.text ...
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckAndAuditAlarm + 4 7C90D3A7 20 Bytes [ 74, 07, 8D, 46, D8, 3B, D8, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckByType + 4 7C90D3BC 25 Bytes [ 3B, FE, 8B, C7, 73, 24, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckByTypeAndAuditAlarm + 9 7C90D3D6 1 Byte [ FF ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckByTypeAndAuditAlarm + B 7C90D3D8 53 Bytes [ 72, 09, 83, C0, 28, 3B, C6, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarmByHandle + 2 7C90D40E 8 Bytes [ 0F, B7, 85, 9A, FE, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarmByHandle + B 7C90D417 139 Bytes [ 85, 9A, FE, FF, FF, 89, 45, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAllocateLocallyUniqueId + 5 7C90D4A4 24 Bytes [ 3B, C1, 76, 2B, 2B, C1, 33, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAllocateUserPhysicalPages + 9 7C90D4BD 1 Byte [ FF ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtAllocateUserPhysicalPages + B 7C90D4BF 100 Bytes [ 73, 04, 03, D0, 89, 11, 46, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCallbackReturn + 7 7C90D524 3 Bytes [ 1C, 00, 51 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCallbackReturn + B 7C90D528 117 Bytes [ 70, 18, FF, 15, 0C, 10, 80, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCloseObjectAuditAlarm + 3 7C90D59E 293 Bytes [ 3B, 55, E4, 0F, 85, AC, 01, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCreateJobSet + 3 7C90D6C4 167 Bytes [ FF, 75, AC, 8B, 0D, 5C, 57, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCreateProcessEx + 4 7C90D76D 31 Bytes [ 6A, 0A, 33, C0, 59, 8B, FA, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCreateProfile + F 7C90D78D 10 Bytes CALL 439D1A1B
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCreateSection + 5 7C90D798 86 Bytes [ 00, 40, 8B, 85, CC, FE, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtCreateTimer + 8 7C90D7EF 226 Bytes [ 59, 0C, 2B, D8, 83, C2, 28, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtDeleteValueKey + 5 7C90D8D3 81 Bytes [ 00, 80, 0B, C8, 89, 0B, 8B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtDuplicateToken + 3 7C90D925 95 Bytes CALL 7C90B55C C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtEnumerateValueKey + F 7C90D985 72 Bytes [ 00, 00, 8B, 45, FC, 2B, 45, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtFlushBuffersFile + 4 7C90D9CE 188 Bytes [ 6A, 00, 56, 83, C3, 08, 89, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtGetDevicePowerState + 5 7C90DA8C 215 Bytes [ 00, 8B, 45, FC, 2B, 45, EC, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtListenPort + B 7C90DB64 77 Bytes [ FF, FF, 8B, 45, E0, 8B, 50, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtLockFile + 5 7C90DBB2 1 Byte [ 00 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtLockFile + 7 7C90DBB4 63 Bytes [ 80, 89, 4B, 04, 8B, 48, 04, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtLockVirtualMemory + 8 7C90DBF4 89 Bytes [ 41, 0C, 83, C6, 08, 50, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtMapUserPhysicalPagesScatter + E 7C90DC4E 17 Bytes [ 05, 08, 01, 00, 00, 50, 56, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtMapViewOfSection + B 7C90DC60 41 Bytes [ FF, 2B, 85, E0, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtNotifyChangeDirectoryFile + B 7C90DC8A 62 Bytes [ FF, 8B, 85, D0, FE, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenDirectoryObject + B 7C90DCC9 20 Bytes [ 4B, 75, EF, 57, FF, 35, 7C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenEvent + B 7C90DCDE 37 Bytes [ FF, 8B, 8D, E0, FD, FF, FF, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenFile + 7 7C90DD04 69 Bytes [ 3B, D8, 8B, 7D, B4, 0F, 83, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenKey + E 7C90DD4A 122 Bytes CALL 7C90B445 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenSection + B 7C90DDC5 20 Bytes [ FF, 75, AC, FF, 75, EC, 56, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenSemaphore + B 7C90DDDA 20 Bytes CALL 7C90B411 C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenSymbolicLinkObject + B 7C90DDEF 13 Bytes [ FF, 8B, 47, 10, 01, 85, B4, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenThread + 4 7C90DDFD 48 Bytes [ 0F, 85, D7, 00, 00, 00, 83, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenThreadTokenEx + B 7C90DE2E 20 Bytes [ FF, B5, D0, FE, FF, FF, 56, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenTimer + B 7C90DE43 2 Bytes [ FF, 75 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtOpenTimer + E 7C90DE46 17 Bytes [ 89, 45, FC, 2B, 47, 14, 56, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtPlugPlayControl + B 7C90DE58 20 Bytes [ FF, 75, AC, FF, 75, EC, 56, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtPowerInformation + B 7C90DE6D 65 Bytes [ 8B, 47, 10, 01, 85, B4, FE, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtPrivilegedServiceAuditAlarm + E 7C90DEAF 269 Bytes CALL 7C90B42B C:\WINDOWS\system32\ntdll.dll
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryFullAttributesFile + B 7C90DFBD 41 Bytes [ B5, E0, FD, FF, FF, 8D, 8D, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationFile + B 7C90DFE7 34 Bytes [ 74, 3F, 6A, 02, 53, FF, 75, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationPort + 4 7C90E00A 19 Bytes [ 64, 00, 65, 00, 74, 00, 2E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationProcess + 3 7C90E01E 1 Byte [ E5 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationProcess + 5 7C90E020 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationProcess + 7 7C90E022 7 Bytes [ 64, 00, 65, 00, 74, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationProcess + F 7C90E02A 9 Bytes [ 6B, 00, 75, 00, 6E, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationThread + 4 7C90E034 19 Bytes [ 20, 00, 69, 00, 6B, 00, 6B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationToken + 3 7C90E048 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationToken + 5 7C90E04A 1 Byte [ 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationToken + 7 7C90E04C 7 Bytes [ 69, 00, 6F, 00, 6E, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInformationToken + F 7C90E054 9 Bytes [ 72, 00, 65, 00, 73, 00, 2E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInstallUILanguage + 4 7C90E05E 2 Bytes [ 0A, 00 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryInstallUILanguage + 7 7C90E061 16 Bytes [ 00, 00, 00, D4, 00, 01, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryIntervalProfile + 3 7C90E072 1 Byte [ 64 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryIntervalProfile + 5 7C90E074 1 Byte [ 67 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryIntervalProfile + 7 7C90E076 7 Bytes [ 61, 00, 6E, 00, 67, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryIntervalProfile + F 7C90E07E 9 Bytes [ 74, 00, 69, 00, 6C, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryIoCompletion + 4 7C90E088 19 Bytes [ 74, 00, 20, 00, 6E, 00, 79, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryKey + 3 7C90E09C 1 Byte [ 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryKey + 5 7C90E09E 1 Byte [ 66 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryKey + 7 7C90E0A0 7 Bytes [ 72, 00, 61, 00, 20, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryKey + F 7C90E0A8 9 Bytes [ 6E, 00, 20, 00, 70, 00, 61, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryMultipleValueKey + 4 7C90E0B2 19 Bytes [ 74, 00, 69, 00, 74, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryMutant + 3 7C90E0C6 1 Byte [ 66 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryMutant + 5 7C90E0C8 1 Byte [ 6C ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryMutant + 7 7C90E0CA 7 Bytes [ 65, 00, 72, 00, 65, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryMutant + F 7C90E0D2 9 Bytes [ 65, 00, 6E, 00, 68, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryObject + 4 7C90E0DC 19 Bytes [ 65, 00, 72, 00, 20, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryOpenSubKeys + 3 7C90E0F0 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryOpenSubKeys + 5 7C90E0F2 1 Byte [ 75 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryOpenSubKeys + 7 7C90E0F4 7 Bytes [ 76, 00, E6, 00, 72, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryOpenSubKeys + F 7C90E0FC 9 Bytes [ 6E, 00, 64, 00, 65, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryPerformanceCounter + 4 7C90E106 19 Bytes [ 6C, 00, 6F, 00, 6B, 00, 73, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryQuotaInformationFile + 3 7C90E11A 1 Byte [ 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryQuotaInformationFile + 5 7C90E11C 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryQuotaInformationFile + 7 7C90E11E 7 Bytes [ 20, 00, 66, 00, 6F, 00, 72 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryQuotaInformationFile + F 7C90E126 9 Bytes [ 6B, 00, 65, 00, 72, 00, 74, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySection + 4 7C90E130 19 Bytes [ 0D, 00, 0A, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySecurityObject + 3 7C90E144 1 Byte [ 62 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySecurityObject + 5 7C90E146 1 Byte [ 6C ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySecurityObject + 7 7C90E148 7 Bytes [ 65, 00, 76, 00, 20, 00, 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySecurityObject + F 7C90E150 9 Bytes [ 6B, 00, 6B, 00, 65, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySemaphore + 4 7C90E15A 19 Bytes [ 75, 00, 6E, 00, 64, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySymbolicLinkObject + 3 7C90E16E 1 Byte [ 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySymbolicLinkObject + 5 7C90E170 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySymbolicLinkObject + 7 7C90E172 7 Bytes [ 69, 00, 6E, 00, 67, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySymbolicLinkObject + F 7C90E17A 9 Bytes [ 72, 00, 20, 00, 6F, 00, 6D, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemEnvironmentValue + 4 7C90E184 19 Bytes [ 20, 00, 62, 00, E5, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemEnvironmentValueEx + 3 7C90E198 1 Byte [ 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemEnvironmentValueEx + 5 7C90E19A 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemEnvironmentValueEx + 7 7C90E19C 7 Bytes [ 6F, 00, 6E, 00, 2C, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemEnvironmentValueEx + F 7C90E1A4 9 Bytes [ 64, 00, 61, 00, 20, 00, 62, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemInformation + 4 7C90E1AE 19 Bytes [ 6E, 00, 64, 00, 65, 00, 74, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemTime + 3 7C90E1C2 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemTime + 5 7C90E1C4 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemTime + 7 7C90E1C6 7 Bytes [ 64, 00, 6C, 00, E6, 00, 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQuerySystemTime + F 7C90E1CE 8 Bytes [ 74, 00, 2E, 00, 0D, 00, 0A, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryTimer + 4 7C90E1D8 19 Bytes [ 70, 00, 01, 00, 4D, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryTimerResolution + 3 7C90E1EC 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryTimerResolution + 5 7C90E1EE 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryTimerResolution + 7 7C90E1F0 7 Bytes [ 20, 00, 74, 00, 69, 00, 6C ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryTimerResolution + F 7C90E1F8 9 Bytes [ 20, 00, 75, 00, 64, 00, 73, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryValueKey + 4 7C90E202 19 Bytes [ 75, 00, 62, 00, 6E, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryVirtualMemory + 3 7C90E216 1 Byte [ 6D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryVirtualMemory + 5 7C90E218 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryVirtualMemory + 7 7C90E21A 7 Bytes [ 64, 00, 69, 00, 65, 00, 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryVirtualMemory + F 7C90E222 9 Bytes [ 20, 00, 6B, 00, 61, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueryVolumeInformationFile + 4 7C90E22C 19 Bytes [ 69, 00, 6B, 00, 6B, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueueApcThread + 3 7C90E240 1 Byte [ 2E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueueApcThread + 5 7C90E242 1 Byte [ 0D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueueApcThread + 7 7C90E244 7 Bytes [ 0A, 00, 00, 00, 40, 00, 01 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtQueueApcThread + F 7C90E24C 9 Bytes [ 4D, 00, 65, 00, 64, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRaiseException + 4 7C90E256 19 Bytes [ 74, 00, 20, 00, 6B, 00, 61, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRaiseHardError + 3 7C90E26A 1 Byte [ 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRaiseHardError + 5 7C90E26C 1 Byte [ 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRaiseHardError + 7 7C90E26E 7 Bytes [ 6B, 00, 75, 00, 62, 00, 62 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRaiseHardError + F 7C90E276 9 Bytes [ 65, 00, 73, 00, 20, 00, 75, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadFile + 4 7C90E280 19 Bytes [ 2E, 00, 0D, 00, 0A, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadFileScatter + 3 7C90E294 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadFileScatter + 5 7C90E296 1 Byte [ 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadFileScatter + 7 7C90E298 7 Bytes [ 20, 00, 69, 00, 20, 00, 64 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadFileScatter + F 7C90E2A0 9 Bytes [ 72, 00, 65, 00, 76, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadRequestData + 4 7C90E2AA 19 Bytes [ 20, 00, 6B, 00, 61, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadVirtualMemory + 3 7C90E2BE 1 Byte [ E6 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadVirtualMemory + 5 7C90E2C0 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadVirtualMemory + 7 7C90E2C2 7 Bytes [ 64, 00, 72, 00, 65, 00, 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReadVirtualMemory + F 7C90E2CA 8 Bytes [ 2E, 00, 0D, 00, 0A, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRegisterThreadTerminatePort + 4 7C90E2D4 19 Bytes [ 40, 00, 01, 00, 49, 00, 2F, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReleaseMutant + 3 7C90E2E8 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReleaseMutant + 5 7C90E2EA 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReleaseMutant + 7 7C90E2EC 7 Bytes [ 20, 00, 62, 00, 6C, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReleaseMutant + F 7C90E2F4 9 Bytes [ 76, 00, 20, 00, 6E, 00, 75, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReleaseSemaphore + 4 7C90E2FE 19 Bytes [ 73, 00, 74, 00, 69, 00, 6C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRemoveIoCompletion + 5 7C90E314 1 Byte [ 4C ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRemoveIoCompletion + 7 7C90E316 7 Bytes [ 01, 00, 44, 00, 65, 00, 72 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRemoveIoCompletion + F 7C90E31E 9 Bytes [ 20, 00, 65, 00, 72, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRemoveProcessDebug + 4 7C90E328 19 Bytes [ 6B, 00, 6B, 00, 65, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRenameKey + 3 7C90E33C 1 Byte [ 6D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRenameKey + 5 7C90E33E 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRenameKey + 7 7C90E340 7 Bytes [ 64, 00, 69, 00, 65, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRenameKey + F 7C90E348 9 Bytes [ 69, 00, 20, 00, 64, 00, 72, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplaceKey + 4 7C90E352 19 Bytes [ 76, 00, 65, 00, 74, 00, 2E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyPort + 3 7C90E366 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyPort + 5 7C90E368 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyPort + 7 7C90E36A 7 Bytes [ 63, 00, 6F, 00, 64, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyPort + F 7C90E372 9 Bytes [ 2D, 00, 74, 00, 65, 00, 67, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReceivePort + 4 7C90E37C 19 Bytes [ 65, 00, 74, 00, 20, 00, 66, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReceivePortEx + 3 7C90E390 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReceivePortEx + 5 7C90E392 1 Byte [ 6B ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReceivePortEx + 7 7C90E394 7 Bytes [ 6B, 00, 65, 00, 20, 00, 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReceivePortEx + F 7C90E39C 9 Bytes [ 20, 00, 64, 00, 65, 00, 6E, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtReplyWaitReplyPort + 4 7C90E3A6 19 Bytes [ 66, 00, 6C, 00, 65, 00, 72, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestDeviceWakeup + 3 7C90E3BA 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestDeviceWakeup + 5 7C90E3BC 1 Byte [ 67 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestDeviceWakeup + 7 7C90E3BE 7 Bytes [ 6E, 00, 74, 00, 61, 00, 62 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestDeviceWakeup + F 7C90E3C6 9 Bytes [ 65, 00, 6C, 00, 2C, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestPort + 4 7C90E3D0 19 Bytes [ 65, 00, 72, 00, 20, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestWaitReplyPort + 3 7C90E3E4 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestWaitReplyPort + 5 7C90E3E6 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestWaitReplyPort + 7 7C90E3E8 7 Bytes [ 61, 00, 74, 00, 69, 00, 6F ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestWaitReplyPort + F 7C90E3F0 8 Bytes [ 6E, 00, 2E, 00, 0D, 00, 0A, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRequestWakeupLatency + 5 7C90E3FB 18 Bytes [ 00, 5C, 00, 01, 00, 44, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResetEvent + 3 7C90E40E 1 Byte [ 6B ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResetEvent + 5 7C90E410 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResetEvent + 7 7C90E412 7 Bytes [ 64, 00, 65, 00, 73, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResetEvent + F 7C90E41A 9 Bytes [ 69, 00, 6B, 00, 6B, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResetWriteWatch + 4 7C90E424 19 Bytes [ 61, 00, 74, 00, 20, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRestoreKey + 3 7C90E438 1 Byte [ 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRestoreKey + 5 7C90E43A 1 Byte [ 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRestoreKey + 7 7C90E43C 7 Bytes [ 65, 00, 72, 00, 65, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtRestoreKey + F 7C90E444 9 Bytes [ 65, 00, 6E, 00, 20, 00, 44, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResumeProcess + 4 7C90E44E 19 Bytes [ 4C, 00, 2E, 00, 0D, 00, 0A, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResumeThread + 3 7C90E462 1 Byte [ 74 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResumeThread + 5 7C90E464 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResumeThread + 7 7C90E466 7 Bytes [ 6D, 00, 65, 00, 74, 00, 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtResumeThread + F 7C90E46E 9 Bytes [ 65, 00, 72, 00, 20, 00, 76, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveKey + 4 7C90E478 19 Bytes [ 64, 00, 20, 00, 61, 00, 74, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveKeyEx + 3 7C90E48C 1 Byte [ 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveKeyEx + 5 7C90E48E 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveKeyEx + 7 7C90E490 7 Bytes [ 65, 00, 64, 00, 2E, 00, 0D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveKeyEx + F 7C90E498 9 Bytes [ 0A, 00, 00, 00, A8, 00, 01, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSaveMergedKeys + 4 7C90E4A2 19 Bytes [ 75, 00, 6B, 00, 6E, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSecureConnectPort + 3 7C90E4B6 1 Byte [ 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSecureConnectPort + 5 7C90E4B8 1 Byte [ 79 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSecureConnectPort + 7 7C90E4BA 7 Bytes [ 73, 00, 74, 00, 65, 00, 6D ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSecureConnectPort + F 7C90E4C2 9 Bytes [ 65, 00, 74, 00, 20, 00, 6B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetBootEntryOrder + 4 7C90E4CC 19 Bytes [ 6E, 00, 6E, 00, 65, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetBootOptions + 3 7C90E4E0 1 Byte [ 66 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetBootOptions + 5 7C90E4E2 1 Byte [ 62 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetBootOptions + 7 7C90E4E4 7 Bytes [ 72, 00, 79, 00, 64, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetBootOptions + F 7C90E4EC 9 Bytes [ 73, 00, 2C, 00, 20, 00, 64, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetContextThread + 4 7C90E4F6 19 Bytes [ 20, 00, 64, 00, 65, 00, 72, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDebugFilterState + 3 7C90E50A 1 Byte [ 76 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDebugFilterState + 5 7C90E50C 1 Byte [ 61 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDebugFilterState + 7 7C90E50E 7 Bytes [ 72, 00, 20, 00, 6E, 00, 6F ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDebugFilterState + F 7C90E516 9 Bytes [ 67, 00, 65, 00, 6E, 00, 20, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultHardErrorPort + 4 7C90E520 19 Bytes [ 75, 00, 6B, 00, 6E, 00, 69, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultLocale + 3 7C90E534 1 Byte [ 61 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultLocale + 5 7C90E536 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultLocale + 7 7C90E538 7 Bytes [ 67, 00, 2E, 00, 0D, 00, 0A ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultLocale + F 7C90E540 9 Bytes [ 00, 00, 00, 00, 8C, 00, 01, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetDefaultUILanguage + 4 7C90E54A 19 Bytes [ 6E, 00, 6D, 00, 6F, 00, 64, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEaFile + 3 7C90E55E 1 Byte [ 20 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEaFile + 5 7C90E560 1 Byte [ 6B ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEaFile + 7 7C90E562 7 Bytes [ 75, 00, 6E, 00, 6E, 00, 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEaFile + F 7C90E56A 9 Bytes [ 20, 00, 69, 00, 6B, 00, 6B, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEvent + 4 7C90E574 19 Bytes [ 20, 00, 75, 00, 64, 00, 66, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEventBoostPriority + 3 7C90E588 1 Byte [ 64 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEventBoostPriority + 5 7C90E58A 1 Byte [ 61 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEventBoostPriority + 7 7C90E58C 7 Bytes [ 20, 00, 64, 00, 65, 00, 72 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetEventBoostPriority + F 7C90E594 9 Bytes [ 20, 00, 6F, 00, 70, 00, 73, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetHighEventPair + 4 7C90E59E 19 Bytes [ 6F, 00, 64, 00, 20, 00, 65, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetHighWaitLowEventPair + 3 7C90E5B2 1 Byte [ 65 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetHighWaitLowEventPair + 5 7C90E5B4 1 Byte [ 6E ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetHighWaitLowEventPair + 7 7C90E5B6 7 Bytes [ 68, 00, 65, 00, 64, 00, 73 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetHighWaitLowEventPair + F 7C90E5BE 9 Bytes [ 66, 00, 65, 00, 6A, 00, 6C, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetInformationDebugObject + 4 7C90E5C8 19 Bytes [ 0D, 00, 0A, 00, 00, 00, 00, ... ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetInformationFile + 3 7C90E5DC 1 Byte [ 62 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetInformationFile + 5 7C90E5DE 1 Byte [ 6C ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetInformationFile + 7 7C90E5E0 7 Bytes [ 65, 00, 76, 00, 20, 00, 69 ]
.text C:\WINDOWS\system32\wuauclt.exe[2800] ntdll.dll!NtSetInformationFile + F