GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-22 12:34:51
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwAdjustPrivilegesToken [0x8DECD472]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwAlpcConnectPort [0x8DECE340]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwAlpcCreatePort [0x8DECD8A6]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwConnectPort [0x8DECC7EA]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreateFile [0x8DECD02E]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreatePort [0x8DECC544]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreateSection [0x8DECCE84]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreateSymbolicLinkObject [0x8DECD658]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreateThread [0x8DECC112]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwLoadDriver [0x8DECDFC2]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwMakeTemporaryObject [0x8DECCA6E]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwOpenFile [0x8DECD266]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwOpenSection [0x8DECCCFE]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwRequestWaitReplyPort [0x8DECC662]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwSecureConnectPort [0x8DECDD5E]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwSetSystemInformation [0x8DECE170]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwShutdownSystem [0x8DECCA08]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwSystemDebugControl [0x8DECCBF2]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwTerminateProcess [0x8DECC40E]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwTerminateThread [0x8DECC2DC]
SSDT            \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO)                                        ZwCreateThreadEx [0x8DECD9B2]

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!KeSetTimerEx + 34C                                                                                                   824C9910 4 Bytes  [72, D4, EC, 8D]
.text           ntkrnlpa.exe!KeSetTimerEx + 370                                                                                                   824C9934 8 Bytes  [40, E3, EC, 8D, A6, D8, EC, ...]
.text           ntkrnlpa.exe!KeSetTimerEx + 3F4                                                                                                   824C99B8 4 Bytes  JMP 988DECC7 
.text           ntkrnlpa.exe!KeSetTimerEx + 40C                                                                                                   824C99D0 4 Bytes  [2E, D0, EC, 8D]
.text           ntkrnlpa.exe!KeSetTimerEx + 438                                                                                                   824C99FC 4 Bytes  [44, C5, EC, 8D]
.text           ...                                                                                                                               
?               system32\drivers\ccinlja.sys                                                                                                      The system cannot find the path specified. !

---- User code sections - GMER 1.0.15 ----

.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[176] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!LdrLoadDll                                                                      777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!LdrUnloadDll                                                                    777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!LdrGetProcedureAddress                                                          77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtAllocateVirtualMemory                                                         77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtClose                                                                         77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtCreateFile                                                                    77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtCreateProcess                                                                 778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtCreateProcessEx                                                               778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtDeleteFile                                                                    778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtFreeVirtualMemory                                                             77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtLoadDriver                                                                    77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtOpenFile                                                                      778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtProtectVirtualMemory                                                          77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtSetInformationProcess                                                         77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtUnloadDriver                                                                  778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!NtWriteVirtualMemory                                                            778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!KiUserExceptionDispatcher                                                       778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ntdll.dll!RtlAllocateHeap                                                                 778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CreateProcessW                                                               76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CreateProcessA                                                               76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!VirtualProtect                                                               76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileA                                                                    768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!OpenFile                                                                     76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileWithProgressA                                                        76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CopyFileW                                                                    76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileW                                                                    7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CopyFileExW                                                                  7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!DeleteFileW                                                                  7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!DeleteFileA                                                                  7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!DeleteFileA + 3                                                              7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileWithProgressW                                                        768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileExW                                                                  768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!LoadLibraryExW                                                               768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!LoadLibraryW                                                                 768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!LoadLibraryExA                                                               768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!LoadLibraryA                                                                 768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!GetProcAddress                                                               768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!GetModuleHandleW                                                             768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!GetModuleHandleA                                                             768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CreateFileW                                                                  768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CreateFileA                                                                  768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!MoveFileExA                                                                  768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CopyFileA                                                                    768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!CopyFileExA                                                                  769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!WinExec                                                                      769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] kernel32.dll!LoadModule                                                                   7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ADVAPI32.dll!OpenServiceA                                                                 775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ADVAPI32.dll!OpenServiceW                                                                 775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ADVAPI32.dll!CreateServiceW                                                               776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ADVAPI32.dll!CreateServiceA                                                               77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] USER32.dll!mouse_event                                                                    763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] USER32.dll!EndTask                                                                        7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] USER32.dll!keybd_event                                                                    7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] GDI32.dll!BitBlt                                                                          761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] GDI32.dll!CreateDCA                                                                       761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] GDI32.dll!CreateDCW                                                                       761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ole32.dll!CoGetClassObject                                                                762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] ole32.dll!CoCreateInstanceEx                                                              762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] WS2_32.dll!WSASocketW                                                                     779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] WS2_32.dll!WSASocketA                                                                     779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] SHELL32.DLL!ShellExecuteW                                                                 769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] SHELL32.DLL!ShellExecuteExW                                                               769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] SHELL32.DLL!ShellExecuteEx                                                                76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrun.exe[332] SHELL32.DLL!ShellExecuteA                                                                 76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!LdrLoadDll                                                                777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!LdrUnloadDll                                                              777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!LdrGetProcedureAddress                                                    77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtAllocateVirtualMemory                                                   77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtClose                                                                   77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtCreateFile                                                              77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtCreateProcess                                                           778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtCreateProcessEx                                                         778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtDeleteFile                                                              778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtFreeVirtualMemory                                                       77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtLoadDriver                                                              77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtOpenFile                                                                778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtProtectVirtualMemory                                                    77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtSetInformationProcess                                                   77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtUnloadDriver                                                            778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!NtWriteVirtualMemory                                                      778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!KiUserExceptionDispatcher                                                 778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ntdll.dll!RtlAllocateHeap                                                           778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CreateProcessW                                                         76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CreateProcessA                                                         76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!VirtualProtect                                                         76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileA                                                              768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!OpenFile                                                               76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileWithProgressA                                                  76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CopyFileW                                                              76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileW                                                              7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CopyFileExW                                                            7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!DeleteFileW                                                            7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!DeleteFileA                                                            7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!DeleteFileA + 3                                                        7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileWithProgressW                                                  768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileExW                                                            768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!LoadLibraryExW                                                         768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!LoadLibraryW                                                           768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!LoadLibraryExA                                                         768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!LoadLibraryA                                                           768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!GetProcAddress                                                         768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!GetModuleHandleW                                                       768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!GetModuleHandleA                                                       768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CreateFileW                                                            768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CreateFileA                                                            768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!MoveFileExA                                                            768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CopyFileA                                                              768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!CopyFileExA                                                            769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!WinExec                                                                769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] kernel32.dll!LoadModule                                                             7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ADVAPI32.dll!OpenServiceA                                                           775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ADVAPI32.dll!OpenServiceW                                                           775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ADVAPI32.dll!CreateServiceW                                                         776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ADVAPI32.dll!CreateServiceA                                                         77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] USER32.dll!mouse_event                                                              763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] USER32.dll!EndTask                                                                  7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] USER32.dll!keybd_event                                                              7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] GDI32.dll!BitBlt                                                                    761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] GDI32.dll!CreateDCA                                                                 761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] GDI32.dll!CreateDCW                                                                 761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ole32.dll!CoGetClassObject                                                          762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] ole32.dll!CoCreateInstanceEx                                                        762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] WS2_32.dll!WSASocketW                                                               779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] WS2_32.dll!WSASocketA                                                               779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] SHELL32.dll!ShellExecuteW                                                           769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] SHELL32.dll!ShellExecuteExW                                                         769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] SHELL32.dll!ShellExecuteEx                                                          76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\inetsrv\inetinfo.exe[392] SHELL32.dll!ShellExecuteA                                                           76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wininit.exe[604] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\services.exe[652] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!LdrLoadDll                                                                           777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!LdrUnloadDll                                                                         777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!LdrGetProcedureAddress                                                               77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtAllocateVirtualMemory                                                              77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtClose                                                                              77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtCreateFile                                                                         77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtCreateProcess                                                                      778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtCreateProcessEx                                                                    778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtDeleteFile                                                                         778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtFreeVirtualMemory                                                                  77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtLoadDriver                                                                         77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtOpenFile                                                                           778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtProtectVirtualMemory                                                               77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtSetInformationProcess                                                              77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtUnloadDriver                                                                       778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!NtWriteVirtualMemory                                                                 778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!KiUserExceptionDispatcher                                                            778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ntdll.dll!RtlAllocateHeap                                                                      778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CreateProcessW                                                                    76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CreateProcessA                                                                    76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!VirtualProtect                                                                    76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileA                                                                         768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!OpenFile                                                                          76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileWithProgressA                                                             76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CopyFileW                                                                         76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileW                                                                         7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CopyFileExW                                                                       7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!DeleteFileW                                                                       7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!DeleteFileA                                                                       7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!DeleteFileA + 3                                                                   7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileWithProgressW                                                             768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileExW                                                                       768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!LoadLibraryExW                                                                    768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!LoadLibraryW                                                                      768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!LoadLibraryExA                                                                    768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!LoadLibraryA                                                                      768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!GetProcAddress                                                                    768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!GetModuleHandleW                                                                  768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!GetModuleHandleA                                                                  768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CreateFileW                                                                       768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CreateFileA                                                                       768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!MoveFileExA                                                                       768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CopyFileA                                                                         768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!CopyFileExA                                                                       769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!WinExec                                                                           769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] kernel32.dll!LoadModule                                                                        7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ADVAPI32.dll!OpenServiceA                                                                      775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ADVAPI32.dll!OpenServiceW                                                                      775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ADVAPI32.dll!CreateServiceW                                                                    776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ADVAPI32.dll!CreateServiceA                                                                    77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] USER32.dll!mouse_event                                                                         763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] USER32.dll!EndTask                                                                             7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] USER32.dll!keybd_event                                                                         7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] GDI32.dll!BitBlt                                                                               761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] GDI32.dll!CreateDCA                                                                            761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] GDI32.dll!CreateDCW                                                                            761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] WS2_32.dll!WSASocketW                                                                          779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] WS2_32.dll!WSASocketA                                                                          779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ole32.dll!CoGetClassObject                                                                     762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsass.exe[664] ole32.dll!CoCreateInstanceEx                                                                   762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!LdrLoadDll                                                                             777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!LdrUnloadDll                                                                           777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!LdrGetProcedureAddress                                                                 77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtAllocateVirtualMemory                                                                77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtClose                                                                                77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtCreateFile                                                                           77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtCreateProcess                                                                        778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtCreateProcessEx                                                                      778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtDeleteFile                                                                           778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtFreeVirtualMemory                                                                    77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtLoadDriver                                                                           77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtOpenFile                                                                             778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtProtectVirtualMemory                                                                 77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtSetInformationProcess                                                                77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtUnloadDriver                                                                         778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!NtWriteVirtualMemory                                                                   778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!KiUserExceptionDispatcher                                                              778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ntdll.dll!RtlAllocateHeap                                                                        778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CreateProcessW                                                                      76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CreateProcessA                                                                      76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!VirtualProtect                                                                      76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileA                                                                           768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!OpenFile                                                                            76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileWithProgressA                                                               76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CopyFileW                                                                           76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileW                                                                           7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CopyFileExW                                                                         7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!DeleteFileW                                                                         7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!DeleteFileA                                                                         7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!DeleteFileA + 3                                                                     7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileWithProgressW                                                               768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileExW                                                                         768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!LoadLibraryExW                                                                      768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!LoadLibraryW                                                                        768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!LoadLibraryExA                                                                      768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!LoadLibraryA                                                                        768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!GetProcAddress                                                                      768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!GetModuleHandleW                                                                    768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!GetModuleHandleA                                                                    768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CreateFileW                                                                         768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CreateFileA                                                                         768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!MoveFileExA                                                                         768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CopyFileA                                                                           768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!CopyFileExA                                                                         769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!WinExec                                                                             769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] kernel32.dll!LoadModule                                                                          7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ADVAPI32.dll!OpenServiceA                                                                        775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ADVAPI32.dll!OpenServiceW                                                                        775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ADVAPI32.dll!CreateServiceW                                                                      776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ADVAPI32.dll!CreateServiceA                                                                      77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] USER32.dll!mouse_event                                                                           763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] USER32.dll!EndTask                                                                               7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] USER32.dll!keybd_event                                                                           7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] GDI32.dll!BitBlt                                                                                 761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] GDI32.dll!CreateDCA                                                                              761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] GDI32.dll!CreateDCW                                                                              761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ole32.dll!CoGetClassObject                                                                       762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] ole32.dll!CoCreateInstanceEx                                                                     762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] WS2_32.dll!WSASocketW                                                                            779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\lsm.exe[676] WS2_32.dll!WSASocketA                                                                            779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[820] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!LdrLoadDll                                                                          777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!LdrUnloadDll                                                                        777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!LdrGetProcedureAddress                                                              77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtAllocateVirtualMemory                                                             77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtClose                                                                             77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtCreateFile                                                                        77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtCreateProcess                                                                     778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtCreateProcessEx                                                                   778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtDeleteFile                                                                        778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtFreeVirtualMemory                                                                 77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtLoadDriver                                                                        77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtOpenFile                                                                          778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtProtectVirtualMemory                                                              77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtSetInformationProcess                                                             77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtUnloadDriver                                                                      778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!NtWriteVirtualMemory                                                                778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!KiUserExceptionDispatcher                                                           778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ntdll.dll!RtlAllocateHeap                                                                     778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CreateProcessW                                                                   76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CreateProcessA                                                                   76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!VirtualProtect                                                                   76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileA                                                                        768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!OpenFile                                                                         76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileWithProgressA                                                            76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CopyFileW                                                                        76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileW                                                                        7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CopyFileExW                                                                      7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!DeleteFileW                                                                      7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!DeleteFileA                                                                      7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!DeleteFileA + 3                                                                  7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileWithProgressW                                                            768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileExW                                                                      768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!LoadLibraryExW                                                                   768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!LoadLibraryW                                                                     768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!LoadLibraryExA                                                                   768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!LoadLibraryA                                                                     768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!GetProcAddress                                                                   768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!GetModuleHandleW                                                                 768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!GetModuleHandleA                                                                 768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CreateFileW                                                                      768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CreateFileA                                                                      768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!MoveFileExA                                                                      768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CopyFileA                                                                        768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!CopyFileExA                                                                      769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!WinExec                                                                          769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] kernel32.dll!LoadModule                                                                       7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] GDI32.dll!BitBlt                                                                              761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] GDI32.dll!CreateDCA                                                                           761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] GDI32.dll!CreateDCW                                                                           761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] USER32.dll!mouse_event                                                                        763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] USER32.dll!EndTask                                                                            7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] USER32.dll!keybd_event                                                                        7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ADVAPI32.dll!OpenServiceA                                                                     775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ADVAPI32.dll!OpenServiceW                                                                     775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ADVAPI32.dll!CreateServiceW                                                                   776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ADVAPI32.dll!CreateServiceA                                                                   77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] SHELL32.dll!ShellExecuteW                                                                     769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] SHELL32.dll!ShellExecuteExW                                                                   769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] SHELL32.dll!ShellExecuteEx                                                                    76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] SHELL32.dll!ShellExecuteA                                                                     76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] WS2_32.dll!WSASocketW                                                                         779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] WS2_32.dll!WSASocketA                                                                         779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ole32.dll!CoGetClassObject                                                                    762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[876] ole32.dll!CoCreateInstanceEx                                                                  762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[908] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!LdrLoadDll                                           777E7933 5 Bytes  JMP 002431B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!LdrUnloadDll                                         777FE89C 7 Bytes  JMP 00247140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!LdrGetProcedureAddress                               77804F09 5 Bytes  JMP 002419F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtAllocateVirtualMemory                              77817D68 5 Bytes  JMP 00241950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtClose                                              77817F48 5 Bytes  JMP 00247210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtCreateFile                                         77818008 5 Bytes  JMP 002418D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtCreateProcess                                      778180C8 5 Bytes  JMP 00241890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtCreateProcessEx                                    778180D8 5 Bytes  JMP 002419B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtDeleteFile                                         778183E8 5 Bytes  JMP 00241910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtFreeVirtualMemory                                  77818578 5 Bytes  JMP 00241A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtLoadDriver                                         77818698 5 Bytes  JMP 00241970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtOpenFile                                           778187E8 5 Bytes  JMP 002418F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtProtectVirtualMemory                               77818968 5 Bytes  JMP 00241930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtSetInformationProcess                              77818F58 5 Bytes  JMP 002419D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtUnloadDriver                                       778191A8 5 Bytes  JMP 00241990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!NtWriteVirtualMemory                                 778192A8 5 Bytes  JMP 002418B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!KiUserExceptionDispatcher                            778199E8 5 Bytes  JMP 00242240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ntdll.dll!RtlAllocateHeap                                      778258A6 5 Bytes  JMP 00241A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CreateProcessW                                    76881C01 5 Bytes  JMP 00241A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CreateProcessA                                    76881C36 5 Bytes  JMP 00241A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!VirtualProtect                                    76881DD1 5 Bytes  JMP 00241D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileA                                         768824CD 5 Bytes  JMP 00241BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!OpenFile                                          76883569 5 Bytes  JMP 00241B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileWithProgressA                             76885883 5 Bytes  JMP 00241C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CopyFileW                                         76886FAD 5 Bytes  JMP 00241B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileW                                         7688A672 5 Bytes  JMP 00241C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CopyFileExW                                       7688BFA1 7 Bytes  JMP 00241BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!DeleteFileW                                       7689C5C8 5 Bytes  JMP 00241CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!DeleteFileA                                       7689C6E4 2 Bytes  JMP 00241CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!DeleteFileA + 3                                   7689C6E7 2 Bytes  [9A, 89]
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileWithProgressW                             768A104C 5 Bytes  JMP 00241C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileExW                                       768A1070 5 Bytes  JMP 00241C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!LoadLibraryExW                                    768A30C3 7 Bytes  JMP 00241AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!LoadLibraryW                                      768A361F 5 Bytes  JMP 00241D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!LoadLibraryExA                                    768A9469 5 Bytes  JMP 00241AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!LoadLibraryA                                      768A9491 5 Bytes  JMP 00241D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!GetProcAddress                                    768CB8B6 5 Bytes  JMP 00241A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!GetModuleHandleW                                  768CB91E 5 Bytes  JMP 00241D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!GetModuleHandleA                                  768CBB4D 5 Bytes  JMP 00241CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CreateFileW                                       768CCC4E 5 Bytes  JMP 00241B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CreateFileA                                       768CCF71 5 Bytes  JMP 00241B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!MoveFileExA                                       768D0926 5 Bytes  JMP 00241C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CopyFileA                                         768D1F87 5 Bytes  JMP 00241B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!CopyFileExA                                       769110D9 5 Bytes  JMP 00241BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!WinExec                                           769153E7 5 Bytes  JMP 00241D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] kernel32.dll!LoadModule                                        7691553F 5 Bytes  JMP 00241AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] USER32.dll!mouse_event                                         763F1305 5 Bytes  JMP 00242CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] USER32.dll!EndTask                                             7640ACCF 5 Bytes  JMP 00246E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] USER32.dll!keybd_event                                         7641D93C 5 Bytes  JMP 00242B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] GDI32.dll!BitBlt                                               761A6CE7 5 Bytes  JMP 00242E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] GDI32.dll!CreateDCA                                            761AAC01 5 Bytes  JMP 00242840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] GDI32.dll!CreateDCW                                            761AADA5 5 Bytes  JMP 002429D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ADVAPI32.dll!OpenServiceA                                      775DA383 7 Bytes  JMP 00241640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ADVAPI32.dll!OpenServiceW                                      775DFFC3 7 Bytes  JMP 00241480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ADVAPI32.dll!CreateServiceW                                    776038FF 7 Bytes  JMP 00241250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ADVAPI32.dll!CreateServiceA                                    77646C71 7 Bytes  JMP 00241000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] SHELL32.dll!ShellExecuteW                                      769AA2C5 5 Bytes  JMP 00241DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] SHELL32.dll!ShellExecuteExW                                    769FFFBD 5 Bytes  JMP 00241E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] SHELL32.dll!ShellExecuteEx                                     76BA8A6A 5 Bytes  JMP 00241DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] SHELL32.dll!ShellExecuteA                                      76BA8B05 5 Bytes  JMP 00241DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ole32.dll!CoGetClassObject                                     762A6120 5 Bytes  JMP 00246C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] ole32.dll!CoCreateInstanceEx                                   762BE1CB 5 Bytes  JMP 00246B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] WININET.dll!InternetConnectA                                   760E111E 5 Bytes  JMP 00241E30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] WININET.dll!InternetConnectW                                   760F3E01 5 Bytes  JMP 00241E50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] WS2_32.dll!WSASocketW                                          779F34EB 7 Bytes  JMP 00241E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[948] WS2_32.dll!WSASocketA                                          779F8FA9 5 Bytes  JMP 00241E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] SHELL32.dll!ShellExecuteW                                                                    769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] SHELL32.dll!ShellExecuteExW                                                                  769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] SHELL32.dll!ShellExecuteEx                                                                   76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[996] SHELL32.dll!ShellExecuteA                                                                    76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!LdrLoadDll                                                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!LdrUnloadDll                                                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!LdrGetProcedureAddress                                                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtAllocateVirtualMemory                                                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtClose                                                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtCreateFile                                                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtCreateProcess                                                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtCreateProcessEx                                                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtDeleteFile                                                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtFreeVirtualMemory                                                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtLoadDriver                                                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtOpenFile                                                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtProtectVirtualMemory                                                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtSetInformationProcess                                                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtUnloadDriver                                                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!NtWriteVirtualMemory                                                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!KiUserExceptionDispatcher                                                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ntdll.dll!RtlAllocateHeap                                                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CreateProcessW                                                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CreateProcessA                                                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!VirtualProtect                                                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileA                                                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!OpenFile                                                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileWithProgressA                                                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CopyFileW                                                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileW                                                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CopyFileExW                                                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!DeleteFileW                                                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!DeleteFileA                                                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!DeleteFileA + 3                                                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileWithProgressW                                                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileExW                                                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!LoadLibraryExW                                                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!LoadLibraryW                                                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!LoadLibraryExA                                                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!LoadLibraryA                                                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!GetProcAddress                                                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!GetModuleHandleW                                                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!GetModuleHandleA                                                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CreateFileW                                                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CreateFileA                                                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!MoveFileExA                                                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CopyFileA                                                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!CopyFileExA                                                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!WinExec                                                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] kernel32.dll!LoadModule                                                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ADVAPI32.dll!OpenServiceA                                                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ADVAPI32.dll!OpenServiceW                                                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ADVAPI32.dll!CreateServiceW                                                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ADVAPI32.dll!CreateServiceA                                                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ole32.dll!CoGetClassObject                                                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] ole32.dll!CoCreateInstanceEx                                                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] GDI32.dll!BitBlt                                                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] GDI32.dll!CreateDCA                                                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] GDI32.dll!CreateDCW                                                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] USER32.dll!mouse_event                                                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] USER32.dll!EndTask                                                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] USER32.dll!keybd_event                                                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] WS2_32.dll!WSASocketW                                                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\unsecapp.exe[1100] WS2_32.dll!WSASocketA                                                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] WININET.dll!InternetConnectA                                                                760E111E 5 Bytes  JMP 10001E30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] WININET.dll!InternetConnectW                                                                760F3E01 5 Bytes  JMP 10001E50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1104] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[1132] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1148] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!LdrLoadDll                                                                       777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!LdrUnloadDll                                                                     777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!LdrGetProcedureAddress                                                           77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtAllocateVirtualMemory                                                          77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtClose                                                                          77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtCreateFile                                                                     77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtCreateProcess                                                                  778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtCreateProcessEx                                                                778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtDeleteFile                                                                     778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtFreeVirtualMemory                                                              77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtLoadDriver                                                                     77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtOpenFile                                                                       778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtProtectVirtualMemory                                                           77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtSetInformationProcess                                                          77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtUnloadDriver                                                                   778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!NtWriteVirtualMemory                                                             778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!KiUserExceptionDispatcher                                                        778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ntdll.dll!RtlAllocateHeap                                                                  778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CreateProcessW                                                                76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CreateProcessA                                                                76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!VirtualProtect                                                                76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileA                                                                     768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!OpenFile                                                                      76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileWithProgressA                                                         76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CopyFileW                                                                     76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileW                                                                     7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CopyFileExW                                                                   7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!DeleteFileW                                                                   7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!DeleteFileA                                                                   7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!DeleteFileA + 3                                                               7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileWithProgressW                                                         768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileExW                                                                   768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!LoadLibraryExW                                                                768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!LoadLibraryW                                                                  768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!LoadLibraryExA                                                                768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!LoadLibraryA                                                                  768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!GetProcAddress                                                                768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!GetModuleHandleW                                                              768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!GetModuleHandleA                                                              768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CreateFileW                                                                   768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CreateFileA                                                                   768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!MoveFileExA                                                                   768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CopyFileA                                                                     768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!CopyFileExA                                                                   769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!WinExec                                                                       769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] kernel32.dll!LoadModule                                                                    7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ADVAPI32.dll!OpenServiceA                                                                  775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ADVAPI32.dll!OpenServiceW                                                                  775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ADVAPI32.dll!CreateServiceW                                                                776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ADVAPI32.dll!CreateServiceA                                                                77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] USER32.dll!mouse_event                                                                     763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] USER32.dll!EndTask                                                                         7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] USER32.dll!keybd_event                                                                     7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] GDI32.dll!BitBlt                                                                           761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] GDI32.dll!CreateDCA                                                                        761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] GDI32.dll!CreateDCW                                                                        761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] WS2_32.dll!WSASocketW                                                                      779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] WS2_32.dll!WSASocketA                                                                      779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ole32.dll!CoGetClassObject                                                                 762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\winlogon.exe[1228] ole32.dll!CoCreateInstanceEx                                                               762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] shell32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] shell32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] shell32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] shell32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] WinInet.dll!InternetConnectA                                                                760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1496] WinInet.dll!InternetConnectW                                                                760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] SHELL32.dll!ShellExecuteW                                                                    769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] SHELL32.dll!ShellExecuteExW                                                                  769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] SHELL32.dll!ShellExecuteEx                                                                   76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] SHELL32.dll!ShellExecuteA                                                                    76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\nvvsvc.exe[1652] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\aestsrv.exe[1732] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[1800] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!LdrLoadDll                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!LdrUnloadDll                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!LdrGetProcedureAddress                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtAllocateVirtualMemory                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtClose                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtCreateFile                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtCreateProcess                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtCreateProcessEx                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtDeleteFile                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtFreeVirtualMemory                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtLoadDriver                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtOpenFile                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtProtectVirtualMemory                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtSetInformationProcess                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtUnloadDriver                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!NtWriteVirtualMemory                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!KiUserExceptionDispatcher                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ntdll.dll!RtlAllocateHeap                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CreateProcessW                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CreateProcessA                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!VirtualProtect                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileA                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!OpenFile                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileWithProgressA                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CopyFileW                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileW                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CopyFileExW                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!DeleteFileW                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!DeleteFileA                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!DeleteFileA + 3                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileWithProgressW                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileExW                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!LoadLibraryExW                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!LoadLibraryW                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!LoadLibraryExA                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!LoadLibraryA                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!GetProcAddress                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!GetModuleHandleW                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!GetModuleHandleA                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CreateFileW                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CreateFileA                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!MoveFileExA                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CopyFileA                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!CopyFileExA                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!WinExec                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] kernel32.dll!LoadModule                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ADVAPI32.dll!OpenServiceA                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ADVAPI32.dll!OpenServiceW                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ADVAPI32.dll!CreateServiceW                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ADVAPI32.dll!CreateServiceA                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] USER32.dll!mouse_event                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] USER32.dll!EndTask                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] USER32.dll!keybd_event                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] GDI32.dll!BitBlt                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] GDI32.dll!CreateDCA                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] GDI32.dll!CreateDCW                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ole32.dll!CoGetClassObject                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] ole32.dll!CoCreateInstanceEx                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] WS2_32.dll!WSASocketW                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe[1944] WS2_32.dll!WSASocketA                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\brss01a.exe[1968] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\spoolsv.exe[2012] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\System32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!LdrLoadDll                                                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!LdrUnloadDll                                                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!LdrGetProcedureAddress                                                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtAllocateVirtualMemory                                                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtClose                                                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtCreateFile                                                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtCreateProcess                                                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtCreateProcessEx                                                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtDeleteFile                                                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtFreeVirtualMemory                                                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtLoadDriver                                                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtOpenFile                                                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtProtectVirtualMemory                                                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtSetInformationProcess                                                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtUnloadDriver                                                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!NtWriteVirtualMemory                                                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!KiUserExceptionDispatcher                                                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ntdll.dll!RtlAllocateHeap                                                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CreateProcessW                                                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CreateProcessA                                                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!VirtualProtect                                                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileA                                                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!OpenFile                                                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileWithProgressA                                                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CopyFileW                                                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileW                                                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CopyFileExW                                                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!DeleteFileW                                                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!DeleteFileA                                                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!DeleteFileA + 3                                                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileWithProgressW                                                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileExW                                                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!LoadLibraryExW                                                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!LoadLibraryW                                                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!LoadLibraryExA                                                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!LoadLibraryA                                                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!GetProcAddress                                                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!GetModuleHandleW                                                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!GetModuleHandleA                                                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CreateFileW                                                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CreateFileA                                                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!MoveFileExA                                                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CopyFileA                                                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!CopyFileExA                                                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!WinExec                                                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] kernel32.dll!LoadModule                                                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] USER32.dll!mouse_event                                                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] USER32.dll!EndTask                                                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] USER32.dll!keybd_event                                                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] GDI32.dll!BitBlt                                                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] GDI32.dll!CreateDCA                                                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] GDI32.dll!CreateDCW                                                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ADVAPI32.dll!OpenServiceA                                                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ADVAPI32.dll!OpenServiceW                                                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ADVAPI32.dll!CreateServiceW                                                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ADVAPI32.dll!CreateServiceA                                                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] WS2_32.dll!WSASocketW                                                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] WS2_32.dll!WSASocketA                                                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ole32.dll!CoGetClassObject                                                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\CFusionMX7\runtime\bin\jrunsvc.exe[2020] ole32.dll!CoCreateInstanceEx                                                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!LdrLoadDll                                                                                777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!LdrUnloadDll                                                                              777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!LdrGetProcedureAddress                                                                    77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtAllocateVirtualMemory                                                                   77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtClose                                                                                   77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtCreateFile                                                                              77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtCreateProcess                                                                           778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtCreateProcessEx                                                                         778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtDeleteFile                                                                              778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtFreeVirtualMemory                                                                       77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtLoadDriver                                                                              77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtOpenFile                                                                                778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtProtectVirtualMemory                                                                    77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtSetInformationProcess                                                                   77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtUnloadDriver                                                                            778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!NtWriteVirtualMemory                                                                      778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!KiUserExceptionDispatcher                                                                 778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ntdll.dll!RtlAllocateHeap                                                                           778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CreateProcessW                                                                         76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CreateProcessA                                                                         76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!VirtualProtect                                                                         76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileA                                                                              768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!OpenFile                                                                               76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileWithProgressA                                                                  76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CopyFileW                                                                              76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileW                                                                              7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CopyFileExW                                                                            7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!DeleteFileW                                                                            7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!DeleteFileA                                                                            7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!DeleteFileA + 3                                                                        7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileWithProgressW                                                                  768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileExW                                                                            768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!LoadLibraryExW                                                                         768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!LoadLibraryW                                                                           768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!LoadLibraryExA                                                                         768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!LoadLibraryA                                                                           768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!GetProcAddress                                                                         768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!GetModuleHandleW                                                                       768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!GetModuleHandleA                                                                       768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CreateFileW                                                                            768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CreateFileA                                                                            768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!MoveFileExA                                                                            768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CopyFileA                                                                              768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!CopyFileExA                                                                            769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!WinExec                                                                                769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] kernel32.dll!LoadModule                                                                             7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] GDI32.dll!BitBlt                                                                                    761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] GDI32.dll!CreateDCA                                                                                 761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] GDI32.dll!CreateDCW                                                                                 761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] USER32.dll!mouse_event                                                                              763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] USER32.dll!EndTask                                                                                  7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] USER32.dll!keybd_event                                                                              7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ADVAPI32.dll!OpenServiceA                                                                           775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ADVAPI32.dll!OpenServiceW                                                                           775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ADVAPI32.dll!CreateServiceW                                                                         776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ADVAPI32.dll!CreateServiceA                                                                         77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ole32.dll!CoGetClassObject                                                                          762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] ole32.dll!CoCreateInstanceEx                                                                        762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] WS2_32.dll!WSASocketW                                                                               779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\OEM02Mon.exe[2080] WS2_32.dll!WSASocketA                                                                               779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!LdrLoadDll                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!LdrUnloadDll                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!LdrGetProcedureAddress                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtAllocateVirtualMemory                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtClose                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtCreateFile                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtCreateProcess                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtCreateProcessEx                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtDeleteFile                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtFreeVirtualMemory                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtLoadDriver                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtOpenFile                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtProtectVirtualMemory                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtSetInformationProcess                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtUnloadDriver                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!NtWriteVirtualMemory                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!KiUserExceptionDispatcher                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ntdll.dll!RtlAllocateHeap                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CreateProcessW                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CreateProcessA                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!VirtualProtect                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileA                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!OpenFile                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileWithProgressA                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CopyFileW                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileW                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CopyFileExW                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!DeleteFileW                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!DeleteFileA                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!DeleteFileA + 3                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileWithProgressW                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileExW                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!LoadLibraryExW                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!LoadLibraryW                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!LoadLibraryExA                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!LoadLibraryA                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!GetProcAddress                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!GetModuleHandleW                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!GetModuleHandleA                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CreateFileW                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CreateFileA                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!MoveFileExA                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CopyFileA                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!CopyFileExA                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!WinExec                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] kernel32.dll!LoadModule                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ADVAPI32.dll!OpenServiceA                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ADVAPI32.dll!OpenServiceW                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ADVAPI32.dll!CreateServiceW                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ADVAPI32.dll!CreateServiceA                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] USER32.dll!mouse_event                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] USER32.dll!EndTask                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] USER32.dll!keybd_event                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] GDI32.dll!BitBlt                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] GDI32.dll!CreateDCA                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] GDI32.dll!CreateDCW                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ole32.dll!CoGetClassObject                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] ole32.dll!CoCreateInstanceEx                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] WS2_32.dll!WSASocketW                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] WS2_32.dll!WSASocketA                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] SHELL32.dll!ShellExecuteW                             769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] SHELL32.dll!ShellExecuteExW                           769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] SHELL32.dll!ShellExecuteEx                            76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2104] SHELL32.dll!ShellExecuteA                             76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!LdrLoadDll                 777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!LdrUnloadDll               777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!LdrGetProcedureAddress     77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtAllocateVirtualMemory    77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtClose                    77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtCreateFile               77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtCreateProcess            778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtCreateProcessEx          778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtDeleteFile               778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtFreeVirtualMemory        77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtLoadDriver               77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtOpenFile                 778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtProtectVirtualMemory     77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtSetInformationProcess    77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtUnloadDriver             778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!NtWriteVirtualMemory       778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!KiUserExceptionDispatcher  778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ntdll.dll!RtlAllocateHeap            778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CreateProcessW          76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CreateProcessA          76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!VirtualProtect          76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileA               768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!OpenFile                76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileWithProgressA   76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CopyFileW               76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileW               7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CopyFileExW             7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!DeleteFileW             7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!DeleteFileA             7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!DeleteFileA + 3         7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileWithProgressW   768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileExW             768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!LoadLibraryExW          768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!LoadLibraryW            768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!LoadLibraryExA          768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!LoadLibraryA            768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!GetProcAddress          768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!GetModuleHandleW        768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!GetModuleHandleA        768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CreateFileW             768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CreateFileA             768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!MoveFileExA             768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CopyFileA               768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!CopyFileExA             769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!WinExec                 769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] KERNEL32.dll!LoadModule              7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] USER32.dll!mouse_event               763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] USER32.dll!EndTask                   7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] USER32.dll!keybd_event               7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] GDI32.dll!BitBlt                     761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] GDI32.dll!CreateDCA                  761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] GDI32.dll!CreateDCW                  761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ADVAPI32.dll!OpenServiceA            775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ADVAPI32.dll!OpenServiceW            775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ADVAPI32.dll!CreateServiceW          776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ADVAPI32.dll!CreateServiceA          77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ole32.dll!CoGetClassObject           762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] ole32.dll!CoCreateInstanceEx         762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] WS2_32.dll!WSASocketW                779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] WS2_32.dll!WSASocketA                779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] shell32.dll!ShellExecuteW            769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] shell32.dll!ShellExecuteExW          769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] shell32.dll!ShellExecuteEx           76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe[2128] shell32.dll!ShellExecuteA            76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!LdrLoadDll                                                 777E7933 5 Bytes  JMP 001A31B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!LdrUnloadDll                                               777FE89C 7 Bytes  JMP 001A7140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!LdrGetProcedureAddress                                     77804F09 5 Bytes  JMP 001A19F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtAllocateVirtualMemory                                    77817D68 5 Bytes  JMP 001A1950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtClose                                                    77817F48 5 Bytes  JMP 001A7210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtCreateFile                                               77818008 5 Bytes  JMP 001A18D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtCreateProcess                                            778180C8 5 Bytes  JMP 001A1890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtCreateProcessEx                                          778180D8 5 Bytes  JMP 001A19B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtDeleteFile                                               778183E8 5 Bytes  JMP 001A1910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtFreeVirtualMemory                                        77818578 5 Bytes  JMP 001A1A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtLoadDriver                                               77818698 5 Bytes  JMP 001A1970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtOpenFile                                                 778187E8 5 Bytes  JMP 001A18F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtProtectVirtualMemory                                     77818968 5 Bytes  JMP 001A1930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtSetInformationProcess                                    77818F58 5 Bytes  JMP 001A19D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtUnloadDriver                                             778191A8 5 Bytes  JMP 001A1990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!NtWriteVirtualMemory                                       778192A8 5 Bytes  JMP 001A18B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!KiUserExceptionDispatcher                                  778199E8 5 Bytes  JMP 001A2240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ntdll.dll!RtlAllocateHeap                                            778258A6 5 Bytes  JMP 001A1A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CreateProcessW                                          76881C01 5 Bytes  JMP 001A1A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CreateProcessA                                          76881C36 5 Bytes  JMP 001A1A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!VirtualProtect                                          76881DD1 5 Bytes  JMP 001A1D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileA                                               768824CD 5 Bytes  JMP 001A1BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!OpenFile                                                76883569 5 Bytes  JMP 001A1B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileWithProgressA                                   76885883 5 Bytes  JMP 001A1C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CopyFileW                                               76886FAD 5 Bytes  JMP 001A1B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileW                                               7688A672 5 Bytes  JMP 001A1C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CopyFileExW                                             7688BFA1 7 Bytes  JMP 001A1BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!DeleteFileW                                             7689C5C8 5 Bytes  JMP 001A1CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!DeleteFileA                                             7689C6E4 2 Bytes  JMP 001A1CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!DeleteFileA + 3                                         7689C6E7 2 Bytes  [90, 89]
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileWithProgressW                                   768A104C 5 Bytes  JMP 001A1C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileExW                                             768A1070 5 Bytes  JMP 001A1C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!LoadLibraryExW                                          768A30C3 7 Bytes  JMP 001A1AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!LoadLibraryW                                            768A361F 5 Bytes  JMP 001A1D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!LoadLibraryExA                                          768A9469 5 Bytes  JMP 001A1AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!LoadLibraryA                                            768A9491 5 Bytes  JMP 001A1D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!GetProcAddress                                          768CB8B6 5 Bytes  JMP 001A1A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!GetModuleHandleW                                        768CB91E 5 Bytes  JMP 001A1D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!GetModuleHandleA                                        768CBB4D 5 Bytes  JMP 001A1CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CreateFileW                                             768CCC4E 5 Bytes  JMP 001A1B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CreateFileA                                             768CCF71 5 Bytes  JMP 001A1B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!MoveFileExA                                             768D0926 5 Bytes  JMP 001A1C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CopyFileA                                               768D1F87 5 Bytes  JMP 001A1B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!CopyFileExA                                             769110D9 5 Bytes  JMP 001A1BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!WinExec                                                 769153E7 5 Bytes  JMP 001A1D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] kernel32.dll!LoadModule                                              7691553F 5 Bytes  JMP 001A1AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] USER32.dll!mouse_event                                               763F1305 5 Bytes  JMP 001A2CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] USER32.dll!EndTask                                                   7640ACCF 5 Bytes  JMP 001A6E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] USER32.dll!keybd_event                                               7641D93C 5 Bytes  JMP 001A2B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] GDI32.dll!BitBlt                                                     761A6CE7 5 Bytes  JMP 001A2E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] GDI32.dll!CreateDCA                                                  761AAC01 5 Bytes  JMP 001A2840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] GDI32.dll!CreateDCW                                                  761AADA5 5 Bytes  JMP 001A29D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ADVAPI32.dll!OpenServiceA                                            775DA383 7 Bytes  JMP 001A1640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ADVAPI32.dll!OpenServiceW                                            775DFFC3 7 Bytes  JMP 001A1480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ADVAPI32.dll!CreateServiceW                                          776038FF 7 Bytes  JMP 001A1250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ADVAPI32.dll!CreateServiceA                                          77646C71 7 Bytes  JMP 001A1000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ole32.dll!CoGetClassObject                                           762A6120 5 Bytes  JMP 001A6C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] ole32.dll!CoCreateInstanceEx                                         762BE1CB 5 Bytes  JMP 001A6B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] WININET.dll!InternetConnectA                                         760E111E 5 Bytes  JMP 001A1E30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] WININET.dll!InternetConnectW                                         760F3E01 5 Bytes  JMP 001A1E50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] WS2_32.dll!WSASocketW                                                779F34EB 7 Bytes  JMP 001A1E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] WS2_32.dll!WSASocketA                                                779F8FA9 5 Bytes  JMP 001A1E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] SHELL32.dll!ShellExecuteW                                            769AA2C5 5 Bytes  JMP 001A1DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] SHELL32.dll!ShellExecuteExW                                          769FFFBD 5 Bytes  JMP 001A1E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] SHELL32.dll!ShellExecuteEx                                           76BA8A6A 5 Bytes  JMP 001A1DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[2160] SHELL32.dll!ShellExecuteA                                            76BA8B05 5 Bytes  JMP 001A1DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2216] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!LdrLoadDll                                                   777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!LdrUnloadDll                                                 777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!LdrGetProcedureAddress                                       77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtAllocateVirtualMemory                                      77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtClose                                                      77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtCreateFile                                                 77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtCreateProcess                                              778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtCreateProcessEx                                            778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtDeleteFile                                                 778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtFreeVirtualMemory                                          77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtLoadDriver                                                 77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtOpenFile                                                   778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtProtectVirtualMemory                                       77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtSetInformationProcess                                      77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtUnloadDriver                                               778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!NtWriteVirtualMemory                                         778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!KiUserExceptionDispatcher                                    778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ntdll.dll!RtlAllocateHeap                                              778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CreateProcessW                                            76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CreateProcessA                                            76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!VirtualProtect                                            76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileA                                                 768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!OpenFile                                                  76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileWithProgressA                                     76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CopyFileW                                                 76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileW                                                 7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CopyFileExW                                               7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!DeleteFileW                                               7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!DeleteFileA                                               7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!DeleteFileA + 3                                           7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileWithProgressW                                     768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileExW                                               768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!LoadLibraryExW                                            768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!LoadLibraryW                                              768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!LoadLibraryExA                                            768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!LoadLibraryA                                              768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!GetProcAddress                                            768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!GetModuleHandleW                                          768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!GetModuleHandleA                                          768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CreateFileW                                               768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CreateFileA                                               768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!MoveFileExA                                               768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CopyFileA                                                 768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!CopyFileExA                                               769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!WinExec                                                   769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] kernel32.dll!LoadModule                                                7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] USER32.dll!mouse_event                                                 763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] USER32.dll!EndTask                                                     7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] USER32.dll!keybd_event                                                 7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] GDI32.dll!BitBlt                                                       761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] GDI32.dll!CreateDCA                                                    761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] GDI32.dll!CreateDCW                                                    761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ADVAPI32.dll!OpenServiceA                                              775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ADVAPI32.dll!OpenServiceW                                              775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ADVAPI32.dll!CreateServiceW                                            776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ADVAPI32.dll!CreateServiceA                                            77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] SHELL32.dll!ShellExecuteW                                              769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] SHELL32.dll!ShellExecuteExW                                            769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] SHELL32.dll!ShellExecuteEx                                             76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] SHELL32.dll!ShellExecuteA                                              76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] WS2_32.dll!WSASocketW                                                  779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] WS2_32.dll!WSASocketA                                                  779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ole32.dll!CoGetClassObject                                             762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2252] ole32.dll!CoCreateInstanceEx                                           762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!LdrLoadDll                                          777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!LdrUnloadDll                                        777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!LdrGetProcedureAddress                              77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtAllocateVirtualMemory                             77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtClose                                             77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtCreateFile                                        77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtCreateProcess                                     778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtCreateProcessEx                                   778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtDeleteFile                                        778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtFreeVirtualMemory                                 77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtLoadDriver                                        77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtOpenFile                                          778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtProtectVirtualMemory                              77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtSetInformationProcess                             77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtUnloadDriver                                      778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!NtWriteVirtualMemory                                778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!KiUserExceptionDispatcher                           778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ntdll.dll!RtlAllocateHeap                                     778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CreateProcessW                                   76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CreateProcessA                                   76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!VirtualProtect                                   76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileA                                        768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!OpenFile                                         76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileWithProgressA                            76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CopyFileW                                        76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileW                                        7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CopyFileExW                                      7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!DeleteFileW                                      7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!DeleteFileA                                      7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!DeleteFileA + 3                                  7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileWithProgressW                            768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileExW                                      768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!LoadLibraryExW                                   768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!LoadLibraryW                                     768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!LoadLibraryExA                                   768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!LoadLibraryA                                     768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!GetProcAddress                                   768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!GetModuleHandleW                                 768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!GetModuleHandleA                                 768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CreateFileW                                      768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CreateFileA                                      768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!MoveFileExA                                      768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CopyFileA                                        768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!CopyFileExA                                      769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!WinExec                                          769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] kernel32.dll!LoadModule                                       7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ADVAPI32.dll!OpenServiceA                                     775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ADVAPI32.dll!OpenServiceW                                     775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ADVAPI32.dll!CreateServiceW                                   776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ADVAPI32.dll!CreateServiceA                                   77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ole32.dll!CoGetClassObject                                    762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] ole32.dll!CoCreateInstanceEx                                  762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] GDI32.dll!BitBlt                                              761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] GDI32.dll!CreateDCA                                           761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] GDI32.dll!CreateDCW                                           761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] USER32.dll!mouse_event                                        763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] USER32.dll!EndTask                                            7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] USER32.dll!keybd_event                                        7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] WS2_32.dll!WSASocketW                                         779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2288] WS2_32.dll!WSASocketA                                         779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\STacSV.exe[2360] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2400] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!LdrLoadDll                                                       777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!LdrUnloadDll                                                     777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!LdrGetProcedureAddress                                           77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtAllocateVirtualMemory                                          77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtClose                                                          77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtCreateFile                                                     77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtCreateProcess                                                  778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtCreateProcessEx                                                778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtDeleteFile                                                     778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtFreeVirtualMemory                                              77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtLoadDriver                                                     77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtOpenFile                                                       778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtProtectVirtualMemory                                           77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtSetInformationProcess                                          77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtUnloadDriver                                                   778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!NtWriteVirtualMemory                                             778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!KiUserExceptionDispatcher                                        778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ntdll.dll!RtlAllocateHeap                                                  778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CreateProcessW                                                76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CreateProcessA                                                76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!VirtualProtect                                                76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileA                                                     768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!OpenFile                                                      76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileWithProgressA                                         76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CopyFileW                                                     76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileW                                                     7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CopyFileExW                                                   7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!DeleteFileW                                                   7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!DeleteFileA                                                   7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!DeleteFileA + 3                                               7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileWithProgressW                                         768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileExW                                                   768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!LoadLibraryExW                                                768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!LoadLibraryW                                                  768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!LoadLibraryExA                                                768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!LoadLibraryA                                                  768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!GetProcAddress                                                768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!GetModuleHandleW                                              768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!GetModuleHandleA                                              768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CreateFileW                                                   768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CreateFileA                                                   768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!MoveFileExA                                                   768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CopyFileA                                                     768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!CopyFileExA                                                   769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!WinExec                                                       769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] kernel32.dll!LoadModule                                                    7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] USER32.dll!mouse_event                                                     763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] USER32.dll!EndTask                                                         7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] USER32.dll!keybd_event                                                     7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] GDI32.dll!BitBlt                                                           761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] GDI32.dll!CreateDCA                                                        761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] GDI32.dll!CreateDCW                                                        761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ADVAPI32.dll!OpenServiceA                                                  775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ADVAPI32.dll!OpenServiceW                                                  775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ADVAPI32.dll!CreateServiceW                                                776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ADVAPI32.dll!CreateServiceA                                                77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] WS2_32.dll!WSASocketW                                                      779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] WS2_32.dll!WSASocketA                                                      779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ole32.dll!CoGetClassObject                                                 762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2512] ole32.dll!CoCreateInstanceEx                                               762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!LdrLoadDll                                                                            777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!LdrUnloadDll                                                                          777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!LdrGetProcedureAddress                                                                77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtAllocateVirtualMemory                                                               77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtClose                                                                               77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtCreateFile                                                                          77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtCreateProcess                                                                       778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtCreateProcessEx                                                                     778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtDeleteFile                                                                          778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtFreeVirtualMemory                                                                   77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtLoadDriver                                                                          77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtOpenFile                                                                            778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtProtectVirtualMemory                                                                77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtSetInformationProcess                                                               77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtUnloadDriver                                                                        778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!NtWriteVirtualMemory                                                                  778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!KiUserExceptionDispatcher                                                             778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ntdll.dll!RtlAllocateHeap                                                                       778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CreateProcessW                                                                     76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CreateProcessA                                                                     76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!VirtualProtect                                                                     76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileA                                                                          768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!OpenFile                                                                           76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileWithProgressA                                                              76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CopyFileW                                                                          76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileW                                                                          7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CopyFileExW                                                                        7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!DeleteFileW                                                                        7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!DeleteFileA                                                                        7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!DeleteFileA + 3                                                                    7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileWithProgressW                                                              768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileExW                                                                        768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!LoadLibraryExW                                                                     768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!LoadLibraryW                                                                       768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!LoadLibraryExA                                                                     768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!LoadLibraryA                                                                       768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!GetProcAddress                                                                     768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!GetModuleHandleW                                                                   768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!GetModuleHandleA                                                                   768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CreateFileW                                                                        768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CreateFileA                                                                        768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!MoveFileExA                                                                        768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CopyFileA                                                                          768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!CopyFileExA                                                                        769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!WinExec                                                                            769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] kernel32.dll!LoadModule                                                                         7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ADVAPI32.dll!OpenServiceA                                                                       775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ADVAPI32.dll!OpenServiceW                                                                       775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ADVAPI32.dll!CreateServiceW                                                                     776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ADVAPI32.dll!CreateServiceA                                                                     77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] GDI32.dll!BitBlt                                                                                761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] GDI32.dll!CreateDCA                                                                             761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] GDI32.dll!CreateDCW                                                                             761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] USER32.dll!mouse_event                                                                          763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] USER32.dll!EndTask                                                                              7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] USER32.dll!keybd_event                                                                          7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ole32.dll!CoGetClassObject                                                                      762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] ole32.dll!CoCreateInstanceEx                                                                    762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] WS2_32.dll!WSASocketW                                                                           779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] WS2_32.dll!WSASocketA                                                                           779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] SHELL32.dll!ShellExecuteW                                                                       769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] SHELL32.dll!ShellExecuteExW                                                                     769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] SHELL32.dll!ShellExecuteEx                                                                      76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\Dwm.exe[2684] SHELL32.dll!ShellExecuteA                                                                       76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[2692] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\System32\guard32.dll
.text           C:\Windows\System32\svchost.exe[2724] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\System32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[2780] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!LdrLoadDll                                                                                777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!LdrUnloadDll                                                                              777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!LdrGetProcedureAddress                                                                    77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtAllocateVirtualMemory                                                                   77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtClose                                                                                   77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtCreateFile                                                                              77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtCreateProcess                                                                           778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtCreateProcessEx                                                                         778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtDeleteFile                                                                              778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtFreeVirtualMemory                                                                       77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtLoadDriver                                                                              77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtOpenFile                                                                                778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtProtectVirtualMemory                                                                    77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtSetInformationProcess                                                                   77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtUnloadDriver                                                                            778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!NtWriteVirtualMemory                                                                      778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!KiUserExceptionDispatcher                                                                 778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ntdll.dll!RtlAllocateHeap                                                                           778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CreateProcessW                                                                         76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CreateProcessA                                                                         76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!VirtualProtect                                                                         76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileA                                                                              768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!OpenFile                                                                               76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileWithProgressA                                                                  76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CopyFileW                                                                              76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileW                                                                              7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CopyFileExW                                                                            7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!DeleteFileW                                                                            7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!DeleteFileA                                                                            7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!DeleteFileA + 3                                                                        7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileWithProgressW                                                                  768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileExW                                                                            768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!LoadLibraryExW                                                                         768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!LoadLibraryW                                                                           768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!LoadLibraryExA                                                                         768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!LoadLibraryA                                                                           768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!GetProcAddress                                                                         768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!GetModuleHandleW                                                                       768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!GetModuleHandleA                                                                       768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CreateFileW                                                                            768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CreateFileA                                                                            768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!MoveFileExA                                                                            768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CopyFileA                                                                              768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!CopyFileExA                                                                            769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!WinExec                                                                                769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] kernel32.dll!LoadModule                                                                             7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ADVAPI32.dll!OpenServiceA                                                                           775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ADVAPI32.dll!OpenServiceW                                                                           775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ADVAPI32.dll!CreateServiceW                                                                         776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ADVAPI32.dll!CreateServiceA                                                                         77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] GDI32.dll!BitBlt                                                                                    761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] GDI32.dll!CreateDCA                                                                                 761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] GDI32.dll!CreateDCW                                                                                 761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] USER32.dll!mouse_event                                                                              763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] USER32.dll!EndTask                                                                                  7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] USER32.dll!keybd_event                                                                              7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] SHELL32.dll!ShellExecuteW                                                                           769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] SHELL32.dll!ShellExecuteExW                                                                         769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] SHELL32.dll!ShellExecuteEx                                                                          76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] SHELL32.dll!ShellExecuteA                                                                           76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ole32.dll!CoGetClassObject                                                                          762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] ole32.dll!CoCreateInstanceEx                                                                        762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] WS2_32.dll!WSASocketW                                                                               779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] WS2_32.dll!WSASocketA                                                                               779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] WININET.dll!InternetConnectA                                                                        760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Windows\Explorer.EXE[2844] WININET.dll!InternetConnectW                                                                        760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!LdrLoadDll                                                                 777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!LdrUnloadDll                                                               777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!LdrGetProcedureAddress                                                     77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtAllocateVirtualMemory                                                    77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtClose                                                                    77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtCreateFile                                                               77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtCreateProcess                                                            778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtCreateProcessEx                                                          778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtDeleteFile                                                               778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtFreeVirtualMemory                                                        77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtLoadDriver                                                               77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtOpenFile                                                                 778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtProtectVirtualMemory                                                     77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtSetInformationProcess                                                    77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtUnloadDriver                                                             778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!NtWriteVirtualMemory                                                       778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!KiUserExceptionDispatcher                                                  778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ntdll.dll!RtlAllocateHeap                                                            778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CreateProcessW                                                          76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CreateProcessA                                                          76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!VirtualProtect                                                          76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileA                                                               768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!OpenFile                                                                76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileWithProgressA                                                   76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CopyFileW                                                               76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileW                                                               7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CopyFileExW                                                             7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!DeleteFileW                                                             7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!DeleteFileA                                                             7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!DeleteFileA + 3                                                         7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileWithProgressW                                                   768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileExW                                                             768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!LoadLibraryExW                                                          768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!LoadLibraryW                                                            768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!LoadLibraryExA                                                          768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!LoadLibraryA                                                            768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!GetProcAddress                                                          768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!GetModuleHandleW                                                        768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!GetModuleHandleA                                                        768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CreateFileW                                                             768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CreateFileA                                                             768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!MoveFileExA                                                             768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CopyFileA                                                               768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!CopyFileExA                                                             769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!WinExec                                                                 769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] kernel32.dll!LoadModule                                                              7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ADVAPI32.dll!OpenServiceA                                                            775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ADVAPI32.dll!OpenServiceW                                                            775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ADVAPI32.dll!CreateServiceW                                                          776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ADVAPI32.dll!CreateServiceA                                                          77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ole32.dll!CoGetClassObject                                                           762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] ole32.dll!CoCreateInstanceEx                                                         762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] GDI32.dll!BitBlt                                                                     761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] GDI32.dll!CreateDCA                                                                  761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] GDI32.dll!CreateDCW                                                                  761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] USER32.dll!mouse_event                                                               763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] USER32.dll!EndTask                                                                   7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] USER32.dll!keybd_event                                                               7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] WS2_32.dll!WSASocketW                                                                779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\DRIVERS\xaudio.exe[2880] WS2_32.dll!WSASocketA                                                                779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\svchost.exe[3028] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!LdrLoadDll                                                   777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!LdrUnloadDll                                                 777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!LdrGetProcedureAddress                                       77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtAllocateVirtualMemory                                      77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtClose                                                      77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtCreateFile                                                 77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtCreateProcess                                              778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtCreateProcessEx                                            778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtDeleteFile                                                 778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtFreeVirtualMemory                                          77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtLoadDriver                                                 77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtOpenFile                                                   778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtProtectVirtualMemory                                       77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtSetInformationProcess                                      77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtUnloadDriver                                               778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!NtWriteVirtualMemory                                         778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!KiUserExceptionDispatcher                                    778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ntdll.dll!RtlAllocateHeap                                              778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CreateProcessW                                            76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CreateProcessA                                            76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!VirtualProtect                                            76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileA                                                 768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!OpenFile                                                  76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileWithProgressA                                     76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CopyFileW                                                 76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileW                                                 7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CopyFileExW                                               7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!DeleteFileW                                               7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!DeleteFileA                                               7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!DeleteFileA + 3                                           7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileWithProgressW                                     768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileExW                                               768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!LoadLibraryExW                                            768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!LoadLibraryW                                              768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!LoadLibraryExA                                            768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!LoadLibraryA                                              768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!GetProcAddress                                            768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!GetModuleHandleW                                          768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!GetModuleHandleA                                          768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CreateFileW                                               768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CreateFileA                                               768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!MoveFileExA                                               768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CopyFileA                                                 768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!CopyFileExA                                               769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!WinExec                                                   769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] kernel32.dll!LoadModule                                                7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] USER32.dll!mouse_event                                                 763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] USER32.dll!EndTask                                                     7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] USER32.dll!keybd_event                                                 7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] GDI32.dll!BitBlt                                                       761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] GDI32.dll!CreateDCA                                                    761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] GDI32.dll!CreateDCW                                                    761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ADVAPI32.dll!OpenServiceA                                              775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ADVAPI32.dll!OpenServiceW                                              775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ADVAPI32.dll!CreateServiceW                                            776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ADVAPI32.dll!CreateServiceA                                            77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] SHELL32.dll!ShellExecuteW                                              769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] SHELL32.dll!ShellExecuteExW                                            769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] SHELL32.dll!ShellExecuteEx                                             76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] SHELL32.dll!ShellExecuteA                                              76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] WS2_32.dll!WSASocketW                                                  779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] WS2_32.dll!WSASocketA                                                  779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ole32.dll!CoGetClassObject                                             762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] ole32.dll!CoCreateInstanceEx                                           762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] WININET.DLL!InternetConnectA                                           760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[3132] WININET.DLL!InternetConnectW                                           760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!LdrLoadDll                                                                         777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!LdrUnloadDll                                                                       777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!LdrGetProcedureAddress                                                             77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtAllocateVirtualMemory                                                            77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtClose                                                                            77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtCreateFile                                                                       77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtCreateProcess                                                                    778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtCreateProcessEx                                                                  778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtDeleteFile                                                                       778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtFreeVirtualMemory                                                                77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtLoadDriver                                                                       77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtOpenFile                                                                         778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtProtectVirtualMemory                                                             77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtSetInformationProcess                                                            77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtUnloadDriver                                                                     778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!NtWriteVirtualMemory                                                               778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!KiUserExceptionDispatcher                                                          778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ntdll.dll!RtlAllocateHeap                                                                    778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CreateProcessW                                                                  76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CreateProcessA                                                                  76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!VirtualProtect                                                                  76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileA                                                                       768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!OpenFile                                                                        76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileWithProgressA                                                           76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CopyFileW                                                                       76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileW                                                                       7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CopyFileExW                                                                     7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!DeleteFileW                                                                     7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!DeleteFileA                                                                     7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!DeleteFileA + 3                                                                 7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileWithProgressW                                                           768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileExW                                                                     768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!LoadLibraryExW                                                                  768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!LoadLibraryW                                                                    768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!LoadLibraryExA                                                                  768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!LoadLibraryA                                                                    768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!GetProcAddress                                                                  768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!GetModuleHandleW                                                                768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!GetModuleHandleA                                                                768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CreateFileW                                                                     768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CreateFileA                                                                     768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!MoveFileExA                                                                     768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CopyFileA                                                                       768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!CopyFileExA                                                                     769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!WinExec                                                                         769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] kernel32.dll!LoadModule                                                                      7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ADVAPI32.dll!OpenServiceA                                                                    775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ADVAPI32.dll!OpenServiceW                                                                    775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ADVAPI32.dll!CreateServiceW                                                                  776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ADVAPI32.dll!CreateServiceA                                                                  77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] USER32.dll!mouse_event                                                                       763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] USER32.dll!EndTask                                                                           7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] USER32.dll!keybd_event                                                                       7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] GDI32.dll!BitBlt                                                                             761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] GDI32.dll!CreateDCA                                                                          761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] GDI32.dll!CreateDCW                                                                          761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ole32.dll!CoGetClassObject                                                                   762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] ole32.dll!CoCreateInstanceEx                                                                 762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] SHELL32.dll!ShellExecuteW                                                                    769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] SHELL32.dll!ShellExecuteExW                                                                  769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] SHELL32.dll!ShellExecuteEx                                                                   76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] SHELL32.dll!ShellExecuteA                                                                    76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] WS2_32.dll!WSASocketW                                                                        779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\System32\wpcumi.exe[3328] WS2_32.dll!WSASocketA                                                                        779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!LdrLoadDll                                                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!LdrUnloadDll                                                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!LdrGetProcedureAddress                                                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtAllocateVirtualMemory                                                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtClose                                                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtCreateFile                                                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtCreateProcess                                                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtCreateProcessEx                                                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtDeleteFile                                                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtFreeVirtualMemory                                                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtLoadDriver                                                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtOpenFile                                                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtProtectVirtualMemory                                                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtSetInformationProcess                                                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtUnloadDriver                                                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!NtWriteVirtualMemory                                                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!KiUserExceptionDispatcher                                                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ntdll.dll!RtlAllocateHeap                                                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CreateProcessW                                                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CreateProcessA                                                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!VirtualProtect                                                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileA                                                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!OpenFile                                                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileWithProgressA                                                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CopyFileW                                                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileW                                                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CopyFileExW                                                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!DeleteFileW                                                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!DeleteFileA                                                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!DeleteFileA + 3                                                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileWithProgressW                                                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileExW                                                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!LoadLibraryExW                                                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!LoadLibraryW                                                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!LoadLibraryExA                                                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!LoadLibraryA                                                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!GetProcAddress                                                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!GetModuleHandleW                                                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!GetModuleHandleA                                                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CreateFileW                                                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CreateFileA                                                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!MoveFileExA                                                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CopyFileA                                                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!CopyFileExA                                                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!WinExec                                                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] kernel32.dll!LoadModule                                                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ADVAPI32.dll!OpenServiceA                                                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ADVAPI32.dll!OpenServiceW                                                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ADVAPI32.dll!CreateServiceW                                                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ADVAPI32.dll!CreateServiceA                                                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] USER32.dll!mouse_event                                                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] USER32.dll!EndTask                                                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] USER32.dll!keybd_event                                                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] GDI32.dll!BitBlt                                                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] GDI32.dll!CreateDCA                                                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] GDI32.dll!CreateDCW                                                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ole32.dll!CoGetClassObject                                                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] ole32.dll!CoCreateInstanceEx                                                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] WS2_32.dll!WSASocketW                                                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\wbem\wmiprvse.exe[3476] WS2_32.dll!WSASocketA                                                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!LdrLoadDll                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!LdrUnloadDll                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!LdrGetProcedureAddress                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtAllocateVirtualMemory                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtClose                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtCreateFile                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtCreateProcess                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtCreateProcessEx                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtDeleteFile                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtFreeVirtualMemory                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtLoadDriver                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtOpenFile                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtProtectVirtualMemory                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtSetInformationProcess                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtUnloadDriver                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!NtWriteVirtualMemory                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!KiUserExceptionDispatcher                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ntdll.dll!RtlAllocateHeap                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CreateProcessW                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CreateProcessA                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!VirtualProtect                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileA                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!OpenFile                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileWithProgressA                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CopyFileW                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileW                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CopyFileExW                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!DeleteFileW                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!DeleteFileA                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!DeleteFileA + 3                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileWithProgressW                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileExW                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!LoadLibraryExW                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!LoadLibraryW                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!LoadLibraryExA                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!LoadLibraryA                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!GetProcAddress                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!GetModuleHandleW                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!GetModuleHandleA                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CreateFileW                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CreateFileA                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!MoveFileExA                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CopyFileA                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!CopyFileExA                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!WinExec                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] kernel32.dll!LoadModule                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ADVAPI32.dll!OpenServiceA                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ADVAPI32.dll!OpenServiceW                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ADVAPI32.dll!CreateServiceW                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ADVAPI32.dll!CreateServiceA                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] SHELL32.dll!ShellExecuteW                             769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] SHELL32.dll!ShellExecuteExW                           769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] SHELL32.dll!ShellExecuteEx                            76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] SHELL32.dll!ShellExecuteA                             76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] GDI32.dll!BitBlt                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] GDI32.dll!CreateDCA                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] GDI32.dll!CreateDCW                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] USER32.dll!mouse_event                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] USER32.dll!EndTask                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] USER32.dll!keybd_event                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] WS2_32.dll!WSASocketW                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] WS2_32.dll!WSASocketA                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ole32.dll!CoGetClassObject                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Users\Sang\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[3688] ole32.dll!CoCreateInstanceEx                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!LdrLoadDll                                                          777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!LdrUnloadDll                                                        777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!LdrGetProcedureAddress                                              77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtAllocateVirtualMemory                                             77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtClose                                                             77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtCreateFile                                                        77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtCreateProcess                                                     778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtCreateProcessEx                                                   778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtDeleteFile                                                        778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtFreeVirtualMemory                                                 77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtLoadDriver                                                        77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtOpenFile                                                          778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtProtectVirtualMemory                                              77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtSetInformationProcess                                             77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtUnloadDriver                                                      778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!NtWriteVirtualMemory                                                778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!KiUserExceptionDispatcher                                           778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ntdll.dll!RtlAllocateHeap                                                     778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CreateProcessW                                                   76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CreateProcessA                                                   76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!VirtualProtect                                                   76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileA                                                        768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!OpenFile                                                         76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileWithProgressA                                            76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CopyFileW                                                        76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileW                                                        7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CopyFileExW                                                      7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!DeleteFileW                                                      7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!DeleteFileA                                                      7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!DeleteFileA + 3                                                  7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileWithProgressW                                            768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileExW                                                      768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!LoadLibraryExW                                                   768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!LoadLibraryW                                                     768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!LoadLibraryExA                                                   768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!LoadLibraryA                                                     768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!GetProcAddress                                                   768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!GetModuleHandleW                                                 768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!GetModuleHandleA                                                 768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CreateFileW                                                      768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CreateFileA                                                      768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!MoveFileExA                                                      768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CopyFileA                                                        768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!CopyFileExA                                                      769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!WinExec                                                          769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] kernel32.dll!LoadModule                                                       7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] USER32.dll!mouse_event                                                        763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] USER32.dll!EndTask                                                            7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] USER32.dll!keybd_event                                                        7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] GDI32.dll!BitBlt                                                              761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] GDI32.dll!CreateDCA                                                           761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] GDI32.dll!CreateDCW                                                           761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ADVAPI32.dll!OpenServiceA                                                     775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ADVAPI32.dll!OpenServiceW                                                     775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ADVAPI32.dll!CreateServiceW                                                   776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ADVAPI32.dll!CreateServiceA                                                   77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ole32.dll!CoGetClassObject                                                    762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] ole32.dll!CoCreateInstanceEx                                                  762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] SHELL32.dll!ShellExecuteW                                                     769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] SHELL32.dll!ShellExecuteExW                                                   769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] SHELL32.dll!ShellExecuteEx                                                    76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] SHELL32.dll!ShellExecuteA                                                     76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] WS2_32.dll!WSASocketW                                                         779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3900] WS2_32.dll!WSASocketA                                                         779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!LdrLoadDll                                                                                       777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!LdrUnloadDll                                                                                     777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!LdrGetProcedureAddress                                                                           77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtAllocateVirtualMemory                                                                          77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtClose                                                                                          77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtCreateFile                                                                                     77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtCreateProcess                                                                                  778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtCreateProcessEx                                                                                778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtDeleteFile                                                                                     778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtFreeVirtualMemory                                                                              77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtLoadDriver                                                                                     77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtOpenFile                                                                                       778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtProtectVirtualMemory                                                                           77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtSetInformationProcess                                                                          77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtUnloadDriver                                                                                   778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!NtWriteVirtualMemory                                                                             778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!KiUserExceptionDispatcher                                                                        778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ntdll.dll!RtlAllocateHeap                                                                                  778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CreateProcessW                                                                                76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CreateProcessA                                                                                76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!VirtualProtect                                                                                76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileA                                                                                     768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!OpenFile                                                                                      76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileWithProgressA                                                                         76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CopyFileW                                                                                     76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileW                                                                                     7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CopyFileExW                                                                                   7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!DeleteFileW                                                                                   7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!DeleteFileA                                                                                   7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!DeleteFileA + 3                                                                               7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileWithProgressW                                                                         768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileExW                                                                                   768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!LoadLibraryExW                                                                                768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!LoadLibraryW                                                                                  768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!LoadLibraryExA                                                                                768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!LoadLibraryA                                                                                  768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!GetProcAddress                                                                                768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!GetModuleHandleW                                                                              768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!GetModuleHandleA                                                                              768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CreateFileW                                                                                   768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CreateFileA                                                                                   768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!MoveFileExA                                                                                   768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CopyFileA                                                                                     768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!CopyFileExA                                                                                   769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!WinExec                                                                                       769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] kernel32.dll!LoadModule                                                                                    7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] USER32.dll!mouse_event                                                                                     763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] USER32.dll!EndTask                                                                                         7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] USER32.dll!keybd_event                                                                                     7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] GDI32.dll!BitBlt                                                                                           761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] GDI32.dll!CreateDCA                                                                                        761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] GDI32.dll!CreateDCW                                                                                        761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ADVAPI32.dll!OpenServiceA                                                                                  775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ADVAPI32.dll!OpenServiceW                                                                                  775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ADVAPI32.dll!CreateServiceW                                                                                776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ADVAPI32.dll!CreateServiceA                                                                                77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ole32.dll!CoGetClassObject                                                                                 762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] ole32.dll!CoCreateInstanceEx                                                                               762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] WS2_32.dll!WSASocketW                                                                                      779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] WS2_32.dll!WSASocketA                                                                                      779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] shell32.dll!ShellExecuteW                                                                                  769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] shell32.dll!ShellExecuteExW                                                                                769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] shell32.dll!ShellExecuteEx                                                                                 76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\gmer\gmer.exe[3984] shell32.dll!ShellExecuteA                                                                                  76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!LdrLoadDll                                                                                777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!LdrUnloadDll                                                                              777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!LdrGetProcedureAddress                                                                    77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtAllocateVirtualMemory                                                                   77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtClose                                                                                   77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtCreateFile                                                                              77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtCreateProcess                                                                           778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtCreateProcessEx                                                                         778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtDeleteFile                                                                              778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtFreeVirtualMemory                                                                       77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtLoadDriver                                                                              77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtOpenFile                                                                                778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtProtectVirtualMemory                                                                    77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtSetInformationProcess                                                                   77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtUnloadDriver                                                                            778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!NtWriteVirtualMemory                                                                      778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!KiUserExceptionDispatcher                                                                 778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ntdll.dll!RtlAllocateHeap                                                                           778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CreateProcessW                                                                         76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CreateProcessA                                                                         76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!VirtualProtect                                                                         76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileA                                                                              768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!OpenFile                                                                               76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileWithProgressA                                                                  76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CopyFileW                                                                              76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileW                                                                              7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CopyFileExW                                                                            7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!DeleteFileW                                                                            7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!DeleteFileA                                                                            7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!DeleteFileA + 3                                                                        7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileWithProgressW                                                                  768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileExW                                                                            768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!LoadLibraryExW                                                                         768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!LoadLibraryW                                                                           768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!LoadLibraryExA                                                                         768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!LoadLibraryA                                                                           768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!GetProcAddress                                                                         768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!GetModuleHandleW                                                                       768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!GetModuleHandleA                                                                       768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CreateFileW                                                                            768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CreateFileA                                                                            768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!MoveFileExA                                                                            768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CopyFileA                                                                              768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!CopyFileExA                                                                            769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!WinExec                                                                                769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] kernel32.dll!LoadModule                                                                             7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ADVAPI32.dll!OpenServiceA                                                                           775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ADVAPI32.dll!OpenServiceW                                                                           775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ADVAPI32.dll!CreateServiceW                                                                         776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ADVAPI32.dll!CreateServiceA                                                                         77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] GDI32.dll!BitBlt                                                                                    761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] GDI32.dll!CreateDCA                                                                                 761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] GDI32.dll!CreateDCW                                                                                 761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] USER32.dll!mouse_event                                                                              763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] USER32.dll!EndTask                                                                                  7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] USER32.dll!keybd_event                                                                              7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] SHELL32.dll!ShellExecuteW                                                                           769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] SHELL32.dll!ShellExecuteExW                                                                         769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] SHELL32.dll!ShellExecuteEx                                                                          76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] SHELL32.dll!ShellExecuteA                                                                           76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ole32.dll!CoGetClassObject                                                                          762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] ole32.dll!CoCreateInstanceEx                                                                        762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] WS2_32.dll!WSASocketW                                                                               779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] WS2_32.dll!WSASocketA                                                                               779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] WININET.dll!InternetConnectA                                                                        760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Windows\explorer.exe[4076] WININET.dll!InternetConnectW                                                                        760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!LdrLoadDll                                777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!LdrUnloadDll                              777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!LdrGetProcedureAddress                    77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtAllocateVirtualMemory                   77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtClose                                   77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtCreateFile                              77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtCreateProcess                           778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtCreateProcessEx                         778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtDeleteFile                              778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtFreeVirtualMemory                       77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtLoadDriver                              77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtOpenFile                                778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtProtectVirtualMemory                    77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtSetInformationProcess                   77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtUnloadDriver                            778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!NtWriteVirtualMemory                      778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!KiUserExceptionDispatcher                 778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ntdll.dll!RtlAllocateHeap                           778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CreateProcessW                         76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CreateProcessA                         76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!VirtualProtect                         76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileA                              768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!OpenFile                               76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileWithProgressA                  76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CopyFileW                              76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileW                              7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CopyFileExW                            7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!DeleteFileW                            7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!DeleteFileA                            7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!DeleteFileA + 3                        7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileWithProgressW                  768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileExW                            768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!LoadLibraryExW                         768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!LoadLibraryW                           768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!LoadLibraryExA                         768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!LoadLibraryA                           768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!GetProcAddress                         768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!GetModuleHandleW                       768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!GetModuleHandleA                       768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CreateFileW                            768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CreateFileA                            768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!MoveFileExA                            768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CopyFileA                              768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!CopyFileExA                            769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!WinExec                                769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] kernel32.dll!LoadModule                             7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ADVAPI32.dll!OpenServiceA                           775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ADVAPI32.dll!OpenServiceW                           775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ADVAPI32.dll!CreateServiceW                         776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ADVAPI32.dll!CreateServiceA                         77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] USER32.dll!mouse_event                              763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] USER32.dll!EndTask                                  7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] USER32.dll!keybd_event                              7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] GDI32.dll!BitBlt                                    761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] GDI32.dll!CreateDCA                                 761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] GDI32.dll!CreateDCW                                 761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ole32.dll!CoGetClassObject                          762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] ole32.dll!CoCreateInstanceEx                        762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] WS2_32.dll!WSASocketW                               779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] WS2_32.dll!WSASocketA                               779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] SHELL32.dll!ShellExecuteW                           769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] SHELL32.dll!ShellExecuteExW                         769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] SHELL32.dll!ShellExecuteEx                          76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] SHELL32.dll!ShellExecuteA                           76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] WININET.dll!InternetConnectA                        760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4092] WININET.dll!InternetConnectW                        760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!LdrLoadDll                                                                        777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!LdrUnloadDll                                                                      777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!LdrGetProcedureAddress                                                            77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtAllocateVirtualMemory                                                           77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtClose                                                                           77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtCreateFile                                                                      77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtCreateProcess                                                                   778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtCreateProcessEx                                                                 778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtDeleteFile                                                                      778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtFreeVirtualMemory                                                               77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtLoadDriver                                                                      77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtOpenFile                                                                        778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtProtectVirtualMemory                                                            77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtSetInformationProcess                                                           77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtUnloadDriver                                                                    778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!NtWriteVirtualMemory                                                              778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!KiUserExceptionDispatcher                                                         778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ntdll.dll!RtlAllocateHeap                                                                   778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CreateProcessW                                                                 76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CreateProcessA                                                                 76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!VirtualProtect                                                                 76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileA                                                                      768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!OpenFile                                                                       76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileWithProgressA                                                          76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CopyFileW                                                                      76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileW                                                                      7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CopyFileExW                                                                    7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!DeleteFileW                                                                    7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!DeleteFileA                                                                    7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!DeleteFileA + 3                                                                7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileWithProgressW                                                          768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileExW                                                                    768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!LoadLibraryExW                                                                 768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!LoadLibraryW                                                                   768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!LoadLibraryExA                                                                 768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!LoadLibraryA                                                                   768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!GetProcAddress                                                                 768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!GetModuleHandleW                                                               768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!GetModuleHandleA                                                               768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CreateFileW                                                                    768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CreateFileA                                                                    768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!MoveFileExA                                                                    768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CopyFileA                                                                      768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!CopyFileExA                                                                    769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!WinExec                                                                        769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] kernel32.dll!LoadModule                                                                     7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ADVAPI32.dll!OpenServiceA                                                                   775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ADVAPI32.dll!OpenServiceW                                                                   775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ADVAPI32.dll!CreateServiceW                                                                 776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ADVAPI32.dll!CreateServiceA                                                                 77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] USER32.dll!mouse_event                                                                      763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] USER32.dll!EndTask                                                                          7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] USER32.dll!keybd_event                                                                      7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] GDI32.dll!BitBlt                                                                            761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] GDI32.dll!CreateDCA                                                                         761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] GDI32.dll!CreateDCW                                                                         761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] SHELL32.dll!ShellExecuteW                                                                   769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] SHELL32.dll!ShellExecuteExW                                                                 769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] SHELL32.dll!ShellExecuteEx                                                                  76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] SHELL32.dll!ShellExecuteA                                                                   76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ole32.dll!CoGetClassObject                                                                  762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] ole32.dll!CoCreateInstanceEx                                                                762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] WS2_32.dll!WSASocketW                                                                       779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\taskeng.exe[4712] WS2_32.dll!WSASocketA                                                                       779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!LdrLoadDll                                                                  777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!LdrUnloadDll                                                                777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!LdrGetProcedureAddress                                                      77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtAllocateVirtualMemory                                                     77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtClose                                                                     77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtCreateFile                                                                77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtCreateProcess                                                             778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtCreateProcessEx                                                           778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtDeleteFile                                                                778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtFreeVirtualMemory                                                         77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtLoadDriver                                                                77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtOpenFile                                                                  778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtProtectVirtualMemory                                                      77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtSetInformationProcess                                                     77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtUnloadDriver                                                              778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!NtWriteVirtualMemory                                                        778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!KiUserExceptionDispatcher                                                   778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ntdll.dll!RtlAllocateHeap                                                             778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CreateProcessW                                                           76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CreateProcessA                                                           76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!VirtualProtect                                                           76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileA                                                                768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!OpenFile                                                                 76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileWithProgressA                                                    76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CopyFileW                                                                76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileW                                                                7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CopyFileExW                                                              7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!DeleteFileW                                                              7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!DeleteFileA                                                              7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!DeleteFileA + 3                                                          7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileWithProgressW                                                    768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileExW                                                              768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!LoadLibraryExW                                                           768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!LoadLibraryW                                                             768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!LoadLibraryExA                                                           768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!LoadLibraryA                                                             768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!GetProcAddress                                                           768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!GetModuleHandleW                                                         768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!GetModuleHandleA                                                         768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CreateFileW                                                              768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CreateFileA                                                              768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!MoveFileExA                                                              768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CopyFileA                                                                768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!CopyFileExA                                                              769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!WinExec                                                                  769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] kernel32.dll!LoadModule                                                               7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ADVAPI32.dll!OpenServiceA                                                             775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ADVAPI32.dll!OpenServiceW                                                             775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ADVAPI32.dll!CreateServiceW                                                           776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ADVAPI32.dll!CreateServiceA                                                           77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] USER32.dll!mouse_event                                                                763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] USER32.dll!EndTask                                                                    7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] USER32.dll!keybd_event                                                                7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] GDI32.dll!BitBlt                                                                      761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] GDI32.dll!CreateDCA                                                                   761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] GDI32.dll!CreateDCW                                                                   761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ole32.dll!CoGetClassObject                                                            762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] ole32.dll!CoCreateInstanceEx                                                          762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] SHELL32.dll!ShellExecuteW                                                             769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] SHELL32.dll!ShellExecuteExW                                                           769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] SHELL32.dll!ShellExecuteEx                                                            76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] SHELL32.dll!ShellExecuteA                                                             76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] WS2_32.dll!WSASocketW                                                                 779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Windows\system32\SearchIndexer.exe[5168] WS2_32.dll!WSASocketA                                                                 779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!LdrLoadDll                                                           777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!LdrUnloadDll                                                         777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!LdrGetProcedureAddress                                               77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtAllocateVirtualMemory                                              77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtClose                                                              77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtCreateFile                                                         77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtCreateProcess                                                      778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtCreateProcessEx                                                    778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtDeleteFile                                                         778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtFreeVirtualMemory                                                  77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtLoadDriver                                                         77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtOpenFile                                                           778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtProtectVirtualMemory                                               77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtSetInformationProcess                                              77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtUnloadDriver                                                       778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!NtWriteVirtualMemory                                                 778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!KiUserExceptionDispatcher                                            778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ntdll.dll!RtlAllocateHeap                                                      778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CreateProcessW                                                    76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CreateProcessA                                                    76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!VirtualProtect                                                    76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileA                                                         768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!OpenFile                                                          76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileWithProgressA                                             76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CopyFileW                                                         76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileW                                                         7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CopyFileExW                                                       7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!DeleteFileW                                                       7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!DeleteFileA                                                       7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!DeleteFileA + 3                                                   7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileWithProgressW                                             768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileExW                                                       768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!LoadLibraryExW                                                    768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!LoadLibraryW                                                      768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!LoadLibraryExA                                                    768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!LoadLibraryA                                                      768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!GetProcAddress                                                    768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!GetModuleHandleW                                                  768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!GetModuleHandleA                                                  768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CreateFileW                                                       768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CreateFileA                                                       768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!MoveFileExA                                                       768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CopyFileA                                                         768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!CopyFileExA                                                       769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!WinExec                                                           769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] kernel32.dll!LoadModule                                                        7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ADVAPI32.dll!OpenServiceA                                                      775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ADVAPI32.dll!OpenServiceW                                                      775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ADVAPI32.dll!CreateServiceW                                                    776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ADVAPI32.dll!CreateServiceA                                                    77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] WS2_32.dll!WSASocketW                                                          779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] WS2_32.dll!WSASocketA                                                          779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] USER32.dll!mouse_event                                                         763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] USER32.dll!EndTask                                                             7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] USER32.dll!keybd_event                                                         7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] GDI32.dll!BitBlt                                                               761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] GDI32.dll!CreateDCA                                                            761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] GDI32.dll!CreateDCW                                                            761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ole32.dll!CoGetClassObject                                                     762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] ole32.dll!CoCreateInstanceEx                                                   762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] SHELL32.dll!ShellExecuteW                                                      769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] SHELL32.dll!ShellExecuteExW                                                    769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] SHELL32.dll!ShellExecuteEx                                                     76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] SHELL32.dll!ShellExecuteA                                                      76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] WININET.dll!InternetConnectA                                                   760E111E 5 Bytes  JMP 10001E30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[5728] WININET.dll!InternetConnectW                                                   760F3E01 5 Bytes  JMP 10001E50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!LdrLoadDll                                                     777E7933 5 Bytes  JMP 100031B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!LdrUnloadDll                                                   777FE89C 7 Bytes  JMP 10007140 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!LdrGetProcedureAddress                                         77804F09 5 Bytes  JMP 100019F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtAllocateVirtualMemory                                        77817D68 5 Bytes  JMP 10001950 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtClose                                                        77817F48 5 Bytes  JMP 10007210 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtCreateFile                                                   77818008 5 Bytes  JMP 100018D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtCreateProcess                                                778180C8 5 Bytes  JMP 10001890 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtCreateProcessEx                                              778180D8 5 Bytes  JMP 100019B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtDeleteFile                                                   778183E8 5 Bytes  JMP 10001910 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtFreeVirtualMemory                                            77818578 5 Bytes  JMP 10001A30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtLoadDriver                                                   77818698 5 Bytes  JMP 10001970 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtOpenFile                                                     778187E8 5 Bytes  JMP 100018F0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtProtectVirtualMemory                                         77818968 5 Bytes  JMP 10001930 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtSetInformationProcess                                        77818F58 5 Bytes  JMP 100019D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtUnloadDriver                                                 778191A8 5 Bytes  JMP 10001990 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!NtWriteVirtualMemory                                           778192A8 5 Bytes  JMP 100018B0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!KiUserExceptionDispatcher                                      778199E8 5 Bytes  JMP 10002240 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ntdll.dll!RtlAllocateHeap                                                778258A6 5 Bytes  JMP 10001A10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CreateProcessW                                              76881C01 5 Bytes  JMP 10001A70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CreateProcessA                                              76881C36 5 Bytes  JMP 10001A50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!VirtualProtect                                              76881DD1 5 Bytes  JMP 10001D90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileA                                                   768824CD 5 Bytes  JMP 10001BF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!OpenFile                                                    76883569 5 Bytes  JMP 10001B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileWithProgressA                                       76885883 5 Bytes  JMP 10001C70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CopyFileW                                                   76886FAD 5 Bytes  JMP 10001B90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileW                                                   7688A672 5 Bytes  JMP 10001C10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CopyFileExW                                                 7688BFA1 7 Bytes  JMP 10001BD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!DeleteFileW                                                 7689C5C8 5 Bytes  JMP 10001CD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!DeleteFileA                                                 7689C6E4 2 Bytes  JMP 10001CB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!DeleteFileA + 3                                             7689C6E7 2 Bytes  [76, 99] {JBE 0xffffffffffffff9b}
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileWithProgressW                                       768A104C 5 Bytes  JMP 10001C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileExW                                                 768A1070 5 Bytes  JMP 10001C50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!LoadLibraryExW                                              768A30C3 7 Bytes  JMP 10001AF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!LoadLibraryW                                                768A361F 5 Bytes  JMP 10001D50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!LoadLibraryExA                                              768A9469 5 Bytes  JMP 10001AD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!LoadLibraryA                                                768A9491 5 Bytes  JMP 10001D30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!GetProcAddress                                              768CB8B6 5 Bytes  JMP 10001A90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!GetModuleHandleW                                            768CB91E 5 Bytes  JMP 10001D10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!GetModuleHandleA                                            768CBB4D 5 Bytes  JMP 10001CF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CreateFileW                                                 768CCC4E 5 Bytes  JMP 10001B50 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CreateFileA                                                 768CCF71 5 Bytes  JMP 10001B30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!MoveFileExA                                                 768D0926 5 Bytes  JMP 10001C30 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CopyFileA                                                   768D1F87 5 Bytes  JMP 10001B70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!CopyFileExA                                                 769110D9 5 Bytes  JMP 10001BB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!WinExec                                                     769153E7 5 Bytes  JMP 10001D70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] kernel32.dll!LoadModule                                                  7691553F 5 Bytes  JMP 10001AB0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ADVAPI32.dll!OpenServiceA                                                775DA383 7 Bytes  JMP 10001640 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ADVAPI32.dll!OpenServiceW                                                775DFFC3 7 Bytes  JMP 10001480 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ADVAPI32.dll!CreateServiceW                                              776038FF 7 Bytes  JMP 10001250 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ADVAPI32.dll!CreateServiceA                                              77646C71 7 Bytes  JMP 10001000 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] USER32.dll!mouse_event                                                   763F1305 5 Bytes  JMP 10002CE0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] USER32.dll!EndTask                                                       7640ACCF 5 Bytes  JMP 10006E00 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] USER32.dll!keybd_event                                                   7641D93C 5 Bytes  JMP 10002B60 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] GDI32.dll!BitBlt                                                         761A6CE7 5 Bytes  JMP 10002E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] GDI32.dll!CreateDCA                                                      761AAC01 5 Bytes  JMP 10002840 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] GDI32.dll!CreateDCW                                                      761AADA5 5 Bytes  JMP 100029D0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ole32.dll!CoGetClassObject                                               762A6120 5 Bytes  JMP 10006C90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] ole32.dll!CoCreateInstanceEx                                             762BE1CB 5 Bytes  JMP 10006B10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] WS2_32.dll!WSASocketW                                                    779F34EB 7 Bytes  JMP 10001E90 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] WS2_32.dll!WSASocketA                                                    779F8FA9 5 Bytes  JMP 10001E70 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] SHELL32.dll!ShellExecuteW                                                769AA2C5 5 Bytes  JMP 10001DD0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] SHELL32.dll!ShellExecuteExW                                              769FFFBD 5 Bytes  JMP 10001E10 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] SHELL32.dll!ShellExecuteEx                                               76BA8A6A 5 Bytes  JMP 10001DF0 C:\Windows\system32\guard32.dll
.text           C:\Program Files\Windows Media Player\wmpnetwk.exe[6080] SHELL32.dll!ShellExecuteA                                                76BA8B05 5 Bytes  JMP 10001DB0 C:\Windows\system32\guard32.dll

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                             [74247BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                              [742898C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                          [7424D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                    [7423F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                              [74247599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                           [7423E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                               [7427B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                  [7424D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                          [7424012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                           [74240095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                            [742371F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                    [742CD802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                       [742675E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                          [7423DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                    [7423668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                   [742366BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\Explorer.EXE[2844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                      [74241E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown]                                             [74247BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage]                                              [742898C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI]                                          [7424D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode]                                    [7423F527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup]                                              [74247599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC]                                           [7423E43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStreamICM]                               [7427B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStream]                                  [7424D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight]                                          [7424012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth]                                           [74240095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage]                                            [742371F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFileICM]                                    [742CD802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFile]                                       [742675E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics]                                          [7423DAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree]                                                    [7423668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc]                                                   [742366BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT             C:\Windows\explorer.exe[4076] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode]                                      [74241E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                                                           Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                                                           Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                           cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume1                                                                                            fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume2                                                                                            fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume3                                                                                            fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\volmgr \Device\HarddiskVolume4                                                                                            fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice  \Driver\tdx \Device\Udp                                                                                                           cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\tdx \Device\RawIp                                                                                                         cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \FileSystem\fastfat \Fat                                                                                                          fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Files - GMER 1.0.15 ----

File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\3A09BA55d01.info                                                      246 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\3A09BA55d011                                                          31111 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\3A09BA55d011.info                                                     206 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A2399842d01                                                           31111 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A2399842d01.info                                                      246 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\C9B82432d01                                                           31111 bytes
File            C:\Program Files\COMODO\COMODO Internet Security\Quarantine\C9B82432d01.info                                                      246 bytes

---- EOF - GMER 1.0.15 ----
