.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 007A8B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 007A18D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 007A1890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 007A19B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 007A1910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 007A1A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 007A1970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 007A18F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 007A1930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 007A19D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [43, 5F] {INC EBX; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 007A1990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 007A18B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 007A1A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 007A4550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 007A8A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ntdll.dll!LdrGetProcedureAddress 7C9177B8 5 Bytes JMP 007A19F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!DeviceIoControl 7C801625 6 Bytes JMP 5FD40F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 007A1B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 007A1D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 7C801AF1 7 Bytes JMP 007A1AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 007A1AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 007A1D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0E0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F110F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007A1A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007A1A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!TlsGetValue 7C809750 6 Bytes JMP 5FCB0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualAlloc 7C809A61 6 Bytes JMP 5FA20F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadResource 7C809FC5 6 Bytes JMP 5FB80F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 007A1A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 007A1D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetModuleHandleA 7C80B6B1 5 Bytes JMP 007A1CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetModuleHandleW 7C80E44D 5 Bytes JMP 007A1D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetVolumeInformationW 7C80F9F5 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateRemoteThread 7C81043C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateRemoteThread + 4 7C810440 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateThread 7C810647 6 Bytes JMP 5F9F0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 007A1B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!WriteFile 7C810D97 6 Bytes JMP 5FE30F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!TerminateThread 7C81CE13 6 Bytes JMP 5F450F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 007A1C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileW 7C821271 5 Bytes JMP 007A1C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateDirectoryA 7C8217BC 6 Bytes JMP 5FDD0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!OpenFile 7C821992 2 Bytes JMP 007A1B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!OpenFile + 3 7C821995 2 Bytes [F8, 83]
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetVolumeInformationA 7C821BB5 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 007A1BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CopyFileA 7C8286FE 5 Bytes JMP 007A1B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CopyFileW 7C82F88F 5 Bytes JMP 007A1B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!DeleteFileA 7C831EF5 5 Bytes JMP 007A1CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 007A1CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateDirectoryW 7C83241A 6 Bytes JMP 5FE00F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileExW 7C8356A3 5 Bytes JMP 007A1C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileA 7C835ED7 5 Bytes JMP 007A1BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileWithProgressA 7C835EF6 5 Bytes JMP 007A1C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!DebugActiveProcess 7C85A2B3 6 Bytes JMP 5F480F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!MoveFileExA 7C85D653 5 Bytes JMP 007A1C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CopyFileExA 7C85E554 5 Bytes JMP 007A1BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 007A1D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadModule 7C86169E 5 Bytes JMP 007A1AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!SetThreadContext 7C862C89 6 Bytes JMP 5FE60F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateToolhelp32Snapshot 7C864D2F 6 Bytes JMP 5F9C0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegSetValueExW 77DDD747 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegQueryValueW 77DDD85A 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegSetValueExA 77DDEAC7 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!OpenSCManagerW 77DE6F3D 6 Bytes JMP 5FAC0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!OpenServiceW 77DE6FE5 7 Bytes JMP 007A1480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!OpenServiceA 77DF4C56 7 Bytes JMP 007A1640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!OpenSCManagerA 77DF6996 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegQueryValueA 77DFBB75 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!LsaRemoveAccountRights 77E1AB91 6 Bytes JMP 5F0B0F5A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!CreateServiceA 77E37359 7 Bytes JMP 007A1000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!CreateServiceW 77E374F1 7 Bytes JMP 007A1250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!GetKeyState 77D4C379 6 Bytes JMP 5F4B0F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!GetWindowTextW 77D4C9FD 6 Bytes JMP 5FB20F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!GetAsyncKeyState 77D4D051 6 Bytes JMP 5F4E0F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!ShowWindow 77D4D4DE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!ShowWindow + 4 77D4D4E2 2 Bytes [B6, 5F] {MOV DH, 0x5f}
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!SetWinEventHook 77D6E3D3 6 Bytes JMP 5F600F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!SetWindowsHookExW 77D6E621 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!GetWindowTextA 77D6F82E 6 Bytes JMP 5FAF0F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!SetWindowsHookExA 77D702B2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!DdeConnect 77D87DBC 6 Bytes JMP 5F510F5A
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!EndTask 77D89C9D 5 Bytes JMP 007A8700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!RegisterRawInputDevices 77D9C9AA 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[992] USER32.dll!RegisterRawInputDevices + 4 77D9C9AE 2 Bytes [64, 5F]
.text C:\WINDOWS\system32\svchost.exe[992] ole32.dll!CoCreateInstanceEx 77525FB1 5 Bytes JMP 007A8450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] ole32.dll!CoGetClassObject 7753F356 5 Bytes JMP 007A8590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!ShellExecuteExW 7CA0D5FE 5 Bytes JMP 007A1E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!ShellExecuteEx 7CA0FB1C 5 Bytes JMP 007A1DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!ShellExecuteA 7CA0FE44 5 Bytes JMP 007A1DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!Shell_NotifyIconW 7CA37CE1 6 Bytes JMP 5FD10F5A
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!Shell_NotifyIcon 7CA389E7 6 Bytes JMP 5FCE0F5A
.text C:\WINDOWS\system32\svchost.exe[992] SHELL32.dll!ShellExecuteW 7CAB2988 5 Bytes JMP 007A1DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetConnectA 771C30B3 5 Bytes JMP 007A1E30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenUrlA 771C5A11 6 Bytes JMP 5FD70F5A
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetConnectW 771CEDE8 5 Bytes JMP 007A1E50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenUrlW 771D5B5A 6 Bytes JMP 5FDA0F5A
.text C:\WINDOWS\system32\svchost.exe[992] WS2_32.dll!socket 71AB3B91 6 Bytes JMP 5FE90F5A
.text C:\WINDOWS\system32\svchost.exe[992] WS2_32.dll!bind 71AB3E00 6 Bytes JMP 5FEC0F5A
.text C:\WINDOWS\system32\svchost.exe[992] WS2_32.dll!listen 71AB88D3 6 Bytes JMP 5FEF0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00B91950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 00B98B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B918D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B91890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00B919B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 00B91910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 00B91A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 00B91970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 00B918F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B91930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 00B919D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [43, 5F] {INC EBX; POP EDI}
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 00B91990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B918B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 00B91A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00B94550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 00B98A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ntdll.dll!LdrGetProcedureAddress 7C9177B8 5 Bytes JMP 00B919F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!DeviceIoControl 7C801625 6 Bytes JMP 5FD40F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00B91B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00B91D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadLibraryExW 7C801AF1 7 Bytes JMP 00B91AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00B91AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00B91D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0E0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F110F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00B91A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00B91A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!TlsGetValue 7C809750 6 Bytes JMP 5FCB0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!VirtualAlloc 7C809A61 6 Bytes JMP 5FA20F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadResource 7C809FC5 6 Bytes JMP 5FB80F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00B91A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00B91D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!GetModuleHandleA 7C80B6B1 5 Bytes JMP 00B91CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!GetModuleHandleW 7C80E44D 5 Bytes JMP 00B91D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!GetVolumeInformationW 7C80F9F5 6 Bytes JMP 5F6D0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateRemoteThread 7C81043C 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateRemoteThread + 4 7C810440 2 Bytes [05, 5F]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateThread 7C810647 6 Bytes JMP 5F9F0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00B91B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!WriteFile 7C810D97 6 Bytes JMP 5FE30F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!TerminateThread 7C81CE13 6 Bytes JMP 5F450F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 00B91C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileW 7C821271 5 Bytes JMP 00B91C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateDirectoryA 7C8217BC 6 Bytes JMP 5FDD0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!OpenFile 7C821992 2 Bytes JMP 00B91B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!OpenFile + 3 7C821995 2 Bytes [37, 84]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!GetVolumeInformationA 7C821BB5 6 Bytes JMP 5F6A0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 00B91BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CopyFileA 7C8286FE 5 Bytes JMP 00B91B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CopyFileW 7C82F88F 5 Bytes JMP 00B91B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!DeleteFileA 7C831EF5 5 Bytes JMP 00B91CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 00B91CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateDirectoryW 7C83241A 6 Bytes JMP 5FE00F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileExW 7C8356A3 5 Bytes JMP 00B91C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileA 7C835ED7 5 Bytes JMP 00B91BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileWithProgressA 7C835EF6 5 Bytes JMP 00B91C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!DebugActiveProcess 7C85A2B3 6 Bytes JMP 5F480F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!MoveFileExA 7C85D653 5 Bytes JMP 00B91C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CopyFileExA 7C85E554 5 Bytes JMP 00B91BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00B91D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!LoadModule 7C86169E 5 Bytes JMP 00B91AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!SetThreadContext 7C862C89 6 Bytes JMP 5FE60F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] kernel32.dll!CreateToolhelp32Snapshot 7C864D2F 6 Bytes JMP 5F9C0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!GetKeyState 77D4C379 6 Bytes JMP 5F4B0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!GetWindowTextW 77D4C9FD 6 Bytes JMP 5FB20F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!GetAsyncKeyState 77D4D051 6 Bytes JMP 5F4E0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!ShowWindow 77D4D4DE 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!ShowWindow + 4 77D4D4E2 2 Bytes [B6, 5F] {MOV DH, 0x5f}
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!SetWinEventHook 77D6E3D3 6 Bytes JMP 5F600F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!SetWindowsHookExW 77D6E621 6 Bytes JMP 5F1F0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!GetWindowTextA 77D6F82E 6 Bytes JMP 5FAF0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!SetWindowsHookExA 77D702B2 6 Bytes JMP 5F1C0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!DdeConnect 77D87DBC 6 Bytes JMP 5F510F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!EndTask 77D89C9D 5 Bytes JMP 00B98700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!RegisterRawInputDevices 77D9C9AA 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] user32.dll!RegisterRawInputDevices + 4 77D9C9AE 2 Bytes [64, 5F]
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F7F0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F910F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F730F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F7C0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F790F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F8E0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegSetValueExW 77DDD747 6 Bytes JMP 5F850F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegQueryValueW 77DDD85A 6 Bytes JMP 5F8B0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegCreateKeyExA 77DDE9D4 6 Bytes JMP 5F700F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegSetValueExA 77DDEAC7 6 Bytes JMP 5F820F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegOpenKeyA 77DDEFA8 6 Bytes JMP 5F760F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!OpenSCManagerW 77DE6F3D 6 Bytes JMP 5FAC0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!OpenServiceW 77DE6FE5 7 Bytes JMP 00B91480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!OpenServiceA 77DF4C56 7 Bytes JMP 00B91640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!OpenSCManagerA 77DF6996 6 Bytes JMP 5FA90F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!RegQueryValueA 77DFBB75 6 Bytes JMP 5F880F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!LsaRemoveAccountRights 77E1AB91 6 Bytes JMP 5F0B0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!CreateServiceA 77E37359 7 Bytes JMP 00B91000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] advapi32.dll!CreateServiceW 77E374F1 7 Bytes JMP 00B91250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ole32.dll!CoCreateInstanceEx 77525FB1 5 Bytes JMP 00B98450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] ole32.dll!CoGetClassObject 7753F356 5 Bytes JMP 00B98590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!ShellExecuteExW 7CA0D5FE 5 Bytes JMP 00B91E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!ShellExecuteEx 7CA0FB1C 5 Bytes JMP 00B91DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!ShellExecuteA 7CA0FE44 5 Bytes JMP 00B91DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!Shell_NotifyIconW 7CA37CE1 6 Bytes JMP 5FD10F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!Shell_NotifyIcon 7CA389E7 6 Bytes JMP 5FCE0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] shell32.dll!ShellExecuteW 7CAB2988 5 Bytes JMP 00B91DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WININET.dll!InternetConnectA 771C30B3 5 Bytes JMP 00B91E30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WININET.dll!InternetOpenUrlA 771C5A11 6 Bytes JMP 5FD70F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WININET.dll!InternetConnectW 771CEDE8 5 Bytes JMP 00B91E50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WININET.dll!InternetOpenUrlW 771D5B5A 6 Bytes JMP 5FDA0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WS2_32.dll!socket 71AB3B91 6 Bytes JMP 5FE90F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WS2_32.dll!bind 71AB3E00 6 Bytes JMP 5FEC0F5A
.text C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe[1024] WS2_32.dll!listen 71AB88D3 6 Bytes JMP 5FEF0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10008B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtSuspendProcess 7C90DE2E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtSuspendProcess + 4 7C90DE32 2 Bytes [43, 5F] {INC EBX; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 10008A60 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!LdrGetProcedureAddress 7C9177B8 5 Bytes JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!DeviceIoControl 7C801625 6 Bytes JMP 5FD40F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExW 7C801AF1 7 Bytes JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F0E0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F110F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!TlsGetValue 7C809750 6 Bytes JMP 5FCB0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!VirtualAlloc 7C809A61 6 Bytes JMP 5FA20F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadResource 7C809FC5 6 Bytes JMP 5FB80F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetModuleHandleA 7C80B6B1 5 Bytes JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetModuleHandleW 7C80E44D 5 Bytes JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetVolumeInformationW 7C80F9F5 6 Bytes JMP 5F6D0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateRemoteThread 7C81043C 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateRemoteThread + 4 7C810440 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateThread 7C810647 6 Bytes JMP 5F9F0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!WriteFile 7C810D97 6 Bytes JMP 5FDD0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!TerminateThread 7C81CE13 6 Bytes JMP 5F450F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileW 7C821271 5 Bytes JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateDirectoryA 7C8217BC 6 Bytes JMP 5FD70F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!OpenFile 7C821992 2 Bytes JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!OpenFile + 3 7C821995 2 Bytes [7E, 93] {JLE 0xffffffffffffff95}
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!GetVolumeInformationA 7C821BB5 6 Bytes JMP 5F6A0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CopyFileA 7C8286FE 5 Bytes JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CopyFileW 7C82F88F 5 Bytes JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!DeleteFileA 7C831EF5 5 Bytes JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateDirectoryW 7C83241A 6 Bytes JMP 5FDA0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileExW 7C8356A3 5 Bytes JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileA 7C835ED7 5 Bytes JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileWithProgressA 7C835EF6 5 Bytes JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!DebugActiveProcess 7C85A2B3 6 Bytes JMP 5F480F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!MoveFileExA 7C85D653 5 Bytes JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CopyFileExA 7C85E554 5 Bytes JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!LoadModule 7C86169E 5 Bytes JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!SetThreadContext 7C862C89 6 Bytes JMP 5FE00F5A
.text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateToolhelp32Snapshot 7C864D2F 6 Bytes JMP 5F9C0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 6 Bytes JMP 5F7F0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegQueryValueExW 77DD6FFF 6 Bytes JMP 5F910F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExW 77DD776C 6 Bytes JMP 5F730F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExA 77DD7852 6 Bytes JMP 5F7C0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyW 77DD7946 6 Bytes JMP 5F790F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegQueryValueExA 77DD7ABB 6 Bytes JMP 5F8E0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegSetValueExW 77DDD747 6 Bytes JMP 5F850F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegQueryValueW 77DDD85A 6 Bytes JMP 5F8B0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExA 77DDE9D4 6 Bytes JMP 5F700F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegSetValueExA 77DDEAC7 6 Bytes JMP 5F820F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyA 77DDEFA8 6 Bytes JMP 5F760F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!OpenSCManagerW 77DE6F3D 6 Bytes JMP 5FAC0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!OpenServiceW 77DE6FE5 7 Bytes JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!OpenServiceA 77DF4C56 7 Bytes JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!OpenSCManagerA 77DF6996 6 Bytes JMP 5FA90F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!RegQueryValueA 77DFBB75 6 Bytes JMP 5F880F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!LsaRemoveAccountRights 77E1AB91 6 Bytes JMP 5F0B0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!CreateServiceA 77E37359 7 Bytes JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!CreateServiceW 77E374F1 7 Bytes JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!GetKeyState 77D4C379 6 Bytes JMP 5F4B0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!GetWindowTextW 77D4C9FD 6 Bytes JMP 5FB20F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!GetAsyncKeyState 77D4D051 6 Bytes JMP 5F4E0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!ShowWindow 77D4D4DE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!ShowWindow + 4 77D4D4E2 2 Bytes [B6, 5F] {MOV DH, 0x5f}
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!SetWinEventHook 77D6E3D3 6 Bytes JMP 5F600F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!SetWindowsHookExW 77D6E621 6 Bytes JMP 5F1F0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!GetWindowTextA 77D6F82E 6 Bytes JMP 5FAF0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!SetWindowsHookExA 77D702B2 6 Bytes JMP 5F1C0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!DdeConnect 77D87DBC 6 Bytes JMP 5F510F5A
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!EndTask 77D89C9D 5 Bytes JMP 10008700 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!RegisterRawInputDevices 77D9C9AA 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1056] USER32.dll!RegisterRawInputDevices + 4 77D9C9AE 2 Bytes [64, 5F]
.text C:\WINDOWS\system32\svchost.exe[1056] ole32.dll!CoCreateInstanceEx 77525FB1 5 Bytes JMP 10008450 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] ole32.dll!CoGetClassObject 7753F356 5 Bytes JMP 10008590 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!ShellExecuteExW 7CA0D5FE 5 Bytes JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!ShellExecuteEx 7CA0FB1C 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!ShellExecuteA 7CA0FE44 5 Bytes JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!Shell_NotifyIconW 7CA37CE1 6 Bytes JMP 5FD10F5A
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!Shell_NotifyIcon 7CA389E7 6 Bytes JMP 5FCE0F5A
.text C:\WINDOWS\system32\svchost.exe[1056] SHELL32.dll!ShellExecuteW 7CAB2988 5 Bytes JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text C:\WINDOWS\system32\svchost.exe[1056] WS2_32.dll!socket 71AB3B91 6 Bytes JMP 5FE30F5A
.text C:\WINDOWS\system32\svchost.exe[1056] WS2_32.dll!bind 71AB3E00 6 Bytes JMP 5FE60F5A
.text C:\WINDOWS\system32\svchost.exe[1056] WS2_32.dll!listen 71AB88D3 6 Bytes JMP 5FE90F5A