Jintan,
I couldn't download the first link you gave me for RSIT. Is it correct or is something wrong with my computer? ><
When I started GMER, it said it found a modification, which may be the cause of rootkit activity. Does this mean I'll have to reformat sooner or later?
By opening scan, I guess you mean this before it asks the full scan?
Code:
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit quick scan 2009-11-28 23:32:42
Windows 5.1.2600 Service Pack 3
Running: 37ivy1cu.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\afnoipob.sys
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] kkohnpj <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] odozeauk <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
Full Scan.. kinda.
It seems as though I can never copy down the most final output from GMER. At the end, although I've missed seeing it 3 times now, the computer seems to have restarted on its own and Windows produces an error once I load on a user's profile.... so if this is not accurate/sufficient enough, I'll try to find the time to monitor the whole scan again. Sorry.
Code:
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-28 23:41:19
Windows 5.1.2600 Service Pack 3
Running: 37ivy1cu.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\afnoipob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xF4F4A2A0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xF4F497C2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xF4F49E5C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateKey [0xF4F4AA6A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xF4F4951C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xF4F4B776]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xF4F4A486]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xF4F490EA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteKey [0xF4F4A6D4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteValueKey [0xF4F4A884]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0xF4F48E4C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xF4F4B3F8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xF4F49A46]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xF4F4A094]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenProcess [0xF4F48B7C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xF4F49CD6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0xF4F48CF4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xF4F4AE30]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xF4F4963A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xF4F4B194]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xF4F4B5A6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetValueKey [0xF4F4AC30]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xF4F499E0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xF4F49BCA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0xF4F493E6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xF4F492B4]
---- Kernel code sections - GMER 1.0.15 ----
init C:\WINDOWS\system32\drivers\nvax.sys entry point in "init" section [0xF7A8D392]
.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF6434360, 0x37388D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[200] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[252] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[276] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\nvsvc32.exe[416] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe[520] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadResource 7C80A055 7 Bytes JMP 28001E30 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!FindResourceExW 7C80AD28 7 Bytes JMP 28001C70 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!FindResourceW 7C80BC6E 7 Bytes JMP 28001BF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!SizeofResource 7C80BD09 7 Bytes JMP 28001EF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!FindResourceA 7C80BF29 7 Bytes JMP 28001D00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LockResource 7C80CD37 5 Bytes JMP 28001F60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CreateEventA 7C8308B5 5 Bytes JMP 28001850 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!FindResourceExA 7C835FA8 7 Bytes JMP 28001D90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!CryptDeriveKey 77DE9FFD 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!GetWindowLongW 7E4188A6 7 Bytes JMP 28006AF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!PeekMessageW 7E41929B 5 Bytes JMP 280046B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!SetWindowPlacement 7E41DE46 5 Bytes JMP 28005E90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!CreateDialogParamW 7E41EA3B 5 Bytes JMP 28006110 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!LoadImageW 7E427B97 5 Bytes JMP 28006760 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 28003CE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!SetWindowRgn 7E42E528 7 Bytes JMP 28005FD0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!LoadIconW 7E42E8BC 5 Bytes JMP 28006950 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 28006300 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] USER32.dll!TrackPopupMenuEx 7E46CF62 5 Bytes JMP 28004F90 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] SHELL32.dll!Shell_NotifyIconW 7CA2A5BF 5 Bytes JMP 28003430 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ole32.dll!CoInitializeEx 774FEF7B 5 Bytes JMP 28002270 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 28002610 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] ole32.dll!CoRegisterClassObject 77517E90 5 Bytes JMP 28002370 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 2800A0E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 2800A290 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!HttpOpenRequestA 3D94D508 5 Bytes JMP 28009F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[668] WININET.dll!HttpSendRequestA 3D95EE89 5 Bytes JMP 2800A1C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\ctfmon.exe[688] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[812] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\winlogon.exe[860] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\DNA\btdna.exe[888] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[996] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Messenger\msmsgs.exe[1008] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[1068] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[1088] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1256] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1328] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1472] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 01F6ADBD
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] NETAPI32.dll!NetpwPathCanonicalize 5B86A3A9 5 Bytes JMP 01F6AD54
.text C:\WINDOWS\system32\svchost.exe[1516] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1516] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Java\jre6\bin\jusched.exe[1608] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 00C6ADBD
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 10001E30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1644] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 10001E50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[1720] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1784] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\sstray.exe[1808] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe[1856] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1928] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[1996] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\svchost.exe[2544] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\System32\alg.exe[2688] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\System32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wscntfy.exe[2700] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 01111950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 01117210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 011118D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 01111890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 011119B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 01111910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 01111A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 01111970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 011118F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01111930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 011119D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 01111990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 011118B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 01112240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 01111A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 011131B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 01117140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 011119F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01111B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01111D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01111AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01111AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01111D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01111A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01111A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01111A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01111D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 01111CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 01111D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01111B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 01111C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 01111C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 01111B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [8F, 84]
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 01111BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 01111B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 01111B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 01111CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 01111CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 01111C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 01111BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 01111C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileExA 7C85E49B 3 Bytes JMP 01111C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!MoveFileExA + 4 7C85E49F 1 Byte [84]
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CopyFileExA 7C85F39C 3 Bytes JMP 01111BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!CopyFileExA + 4 7C85F3A0 1 Byte [84]
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01111D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 01111AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 01111E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 01111E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 01111480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 01111640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 01111000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 01111250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 01116E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 01112CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] USER32.dll!keybd_event 7E466783 5 Bytes JMP 01112B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 01112E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 01112840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 011129D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 01116B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 01116C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 01111E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 01111DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 01111DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TVersity\Media Server\MediaServer.exe[2708] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 01111DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 01071950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 01077210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 010718D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 01071890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 010719B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 01071910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 01071A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 01071970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 010718F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01071930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 010719D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 01071990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 010718B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 01072240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 01071A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 010731B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 01077140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 010719F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01071B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01071D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01071AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01071AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01071D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01071A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01071A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01071A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01071D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 01071CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 01071D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01071B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 01071C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 01071C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 01071B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [85, 84]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 01071BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 01071B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 01071B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 01071CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 01071CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 01071C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 01071BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 01071C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 01071C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 01071BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01071D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 01071AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 01071480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 01071640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 01071000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 01071250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 01071E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 01071E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 01072E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 01072840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 010729D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 01076E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 01072CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] USER32.dll!keybd_event 7E466783 5 Bytes JMP 01072B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 01071E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 01071DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 01071DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 01071DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 01076B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 01076C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] WININET.dll!InternetConnectA 3D94DEAE 5 Bytes JMP 01071E30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3084] WININET.dll!InternetConnectW 3D94F862 5 Bytes JMP 01071E50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 10001E90 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] WS2_32.dll!WSASocketA 71AB8B6A 5 Bytes JMP 10001E70 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] SHELL32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] SHELL32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] SHELL32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[4088] SHELL32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10007210 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 10002240 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 100031B0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 10007140 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!OpenFile 7C821982 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!OpenFile + 3 7C821985 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] USER32.dll!EndTask 7E45A0A5 5 Bytes JMP 10006E00 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] USER32.dll!mouse_event 7E46673F 5 Bytes JMP 10002CE0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] USER32.dll!keybd_event 7E466783 5 Bytes JMP 10002B60 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] GDI32.dll!BitBlt 77F16F79 5 Bytes JMP 10002E70 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10002840 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 100029D0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ole32.dll!CoCreateInstanceEx 77500526 5 Bytes JMP 10006B10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ole32.dll!CoGetClassObject 775156C5 5 Bytes JMP 10006C90 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ADVAPI32.dll!OpenServiceW 77DE6FFD 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ADVAPI32.dll!OpenServiceA 77DF4C66 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ADVAPI32.dll!CreateServiceA 77E37211 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] ADVAPI32.dll!CreateServiceW 77E373A9 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] shell32.dll!ShellExecuteExW 7CA0996B 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] shell32.dll!ShellExecuteEx 7CA40EB5 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] shell32.dll!ShellExecuteA 7CA411E0 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll
.text C:\Documents and Settings\Admin\My Documents\Downloads\37ivy1cu.exe[4352] shell32.dll!ShellExecuteW 7CAB5D48 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\bridge.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\bridge.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\bridge.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\bridge.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F73DF950] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F73DF990] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F73DF710] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F73DF770] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] kkohnpj <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] odozeauk <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@DisplayName Time Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj@Description Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\kkohnpj\Parameters@ServiceDll C:\WINDOWS\system32\nxhsekli.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@DisplayName Windows Installer
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk@Description Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\odozeauk\Parameters@ServiceDll C:\WINDOWS\system32\nxhsekli.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@DisplayName Time Security
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj@Description Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kkohnpj\Parameters@ServiceDll C:\WINDOWS\system32\nxhsekli.dll
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@DisplayName Windows Installer
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk@Description Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\odozeauk\Parameters@ServiceDll C:\WINDOWS\system32\nxhsekli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SUPER
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SUPER @SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SUPER @Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @DisplayName SUPER ? Version 2009.bld.35 (Jan 5, 2009)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @UninstallString C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @InstallDate 2009-01-27 20:22:53
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @InstallLocation C:\Program Files\eRightSoft\SUPER
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @InstallSource G:
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @DisplayIcon C:\Program Files\eRightSoft\SUPER\SUPER.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @DisplayVersion Version 2009.bld.35 (Jan 5, 2009)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @VersionMajor 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @VersionMinor 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @Publisher eRightSoft
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @HelpLink http://www.eRightSoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @URLInfoAbout http://www.eRightSoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @URLUpdateInfo http://www.eRightSoft.com
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SUPER @Contact support@eRightSoft.com
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FriendlyName Indeo? video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@CLSID {1F73E9B1-8C3A-11D0-A3BE-00A0C9244436}
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FilterData 0x02 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@EncoderType 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SUPER ?Version 2009.bld.35 (Jan 5, 2009)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SUPER ?Version 2009.bld.35 (Jan 5, 2009)@Order 0x08 0x00 0x00 0x00 ...