.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\syswow64\USER32.dll!SetWinEventHook 00000000766eee09 5 bytes JMP 00000001002401f8
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 00000000766f3982 5 bytes JMP 00000001002403fc
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 00000000766f7603 5 bytes JMP 0000000100240804
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 00000000766f835c 5 bytes JMP 0000000100240600
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 000000007670f52b 5 bytes JMP 0000000100240a08
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000076ce5181 5 bytes JMP 0000000100251014
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000076ce5254 5 bytes JMP 0000000100250804
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 0000000076ce53d5 5 bytes JMP 0000000100250a08
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 0000000076ce54c2 5 bytes JMP 0000000100250c0c
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 0000000076ce55e2 5 bytes JMP 0000000100250e10
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 0000000076ce567c 5 bytes JMP 00000001002501f8
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 0000000076ce589f 5 bytes JMP 00000001002503fc
.text C:\Program Files (x86)\Common Files\Motive\McciCMService.exe[2756] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000076ce5a22 5 bytes JMP 0000000100250600
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771dfaa0 5 bytes JMP 0000000100030600
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771dfb38 5 bytes JMP 0000000100030804
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 00000000771dfc90 5 bytes JMP 0000000100030c0c
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771e0018 5 bytes JMP 0000000100030a08
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 00000000771e1900 5 bytes JMP 0000000100030e10
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000771fc45a 5 bytes JMP 00000001000301f8
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077201217 5 bytes JMP 00000001000303fc
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000753ea30a 1 byte [62]
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\USER32.dll!SetWinEventHook 00000000766eee09 5 bytes JMP 00000001002401f8
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 00000000766f3982 5 bytes JMP 00000001002403fc
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 00000000766f7603 5 bytes JMP 0000000100240804
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 00000000766f835c 5 bytes JMP 0000000100240600
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 000000007670f52b 5 bytes JMP 0000000100240a08
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000076ce5181 5 bytes JMP 0000000100251014
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000076ce5254 5 bytes JMP 0000000100250804
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 0000000076ce53d5 5 bytes JMP 0000000100250a08
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 0000000076ce54c2 5 bytes JMP 0000000100250c0c
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 0000000076ce55e2 5 bytes JMP 0000000100250e10
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 0000000076ce567c 5 bytes JMP 00000001002501f8
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 0000000076ce589f 5 bytes JMP 00000001002503fc
.text C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe[2836] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000076ce5a22 5 bytes JMP 0000000100250600
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077003ae0 5 bytes JMP 000000010044075c
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077007a90 5 bytes JMP 00000001004403a4
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 00000000770313c0 5 bytes JMP 0000000077190470
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077031410 5 bytes JMP 0000000077190460
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077031490 5 bytes JMP 0000000100440b14
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00000000770314f0 5 bytes JMP 0000000100440ecc
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077031570 5 bytes JMP 0000000077190370
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 00000000770315c0 5 bytes JMP 0000000077190480
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 00000000770315d0 5 bytes JMP 000000010044163c
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077031680 5 bytes JMP 0000000077190320
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000770316b0 5 bytes JMP 00000000771903b0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 00000000770316d0 5 bytes JMP 0000000077190390
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077031710 5 bytes JMP 00000000771902e0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077031760 5 bytes JMP 0000000077190440
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077031790 5 bytes JMP 00000000771902d0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 00000000770317b0 5 bytes JMP 0000000077190310
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 00000000770317f0 5 bytes JMP 00000000771903c0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077031810 5 bytes JMP 0000000100441284
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077031840 5 bytes JMP 00000000771903f0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 00000000770319a0 1 byte JMP 0000000077190230
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry + 2 00000000770319a2 3 bytes {JMP 0x15e890}
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077031b60 5 bytes JMP 0000000077190490
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077031b90 5 bytes JMP 00000000771903a0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077031c70 5 bytes JMP 00000000771902f0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077031c80 5 bytes JMP 0000000077190350
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077031ce0 5 bytes JMP 0000000077190290
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077031d70 5 bytes JMP 00000000771902b0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077031d90 5 bytes JMP 00000000771903d0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077031da0 1 byte JMP 0000000077190330
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer + 2 0000000077031da2 3 bytes {JMP 0x15e590}
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077031e10 5 bytes JMP 0000000077190410
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077031e40 5 bytes JMP 0000000077190240
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077032100 5 bytes JMP 00000000771901e0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 00000000770321c0 1 byte JMP 0000000077190250
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry + 2 00000000770321c2 3 bytes {JMP 0x15e090}
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 00000000770321f0 5 bytes JMP 00000000771904a0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077032200 5 bytes JMP 00000000771904b0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077032230 5 bytes JMP 0000000077190300
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077032240 5 bytes JMP 0000000077190360
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 00000000770322a0 5 bytes JMP 00000000771902a0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 00000000770322f0 5 bytes JMP 00000000771902c0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077032320 5 bytes JMP 0000000077190380
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077032330 5 bytes JMP 0000000077190340
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077032620 5 bytes JMP 0000000077190450
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077032820 5 bytes JMP 0000000077190260
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077032830 5 bytes JMP 0000000077190270
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077032840 5 bytes JMP 00000001004419f4
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077032a00 5 bytes JMP 00000000771901f0
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077032a10 5 bytes JMP 0000000077190210
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077032a80 5 bytes JMP 0000000077190200
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077032ae0 5 bytes JMP 0000000077190420
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077032af0 5 bytes JMP 0000000077190430
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077032b00 5 bytes JMP 0000000077190220
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077032be0 5 bytes JMP 0000000077190280
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefd1f6e00 5 bytes JMP 000007ff7d211dac
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefd1f6f2c 5 bytes JMP 000007ff7d210ecc
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefd1f7220 5 bytes JMP 000007ff7d211284
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefd1f739c 5 bytes JMP 000007ff7d21163c
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefd1f7538 5 bytes JMP 000007ff7d2119f4
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefd1f75e8 5 bytes JMP 000007ff7d2103a4
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefd1f790c 5 bytes JMP 000007ff7d21075c
.text C:\Program Files\Common Files\Motive\McciCMService.exe[2884] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefd1f7ab4 5 bytes JMP 000007ff7d210b14
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771dfaa0 5 bytes JMP 0000000100030600
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771dfb38 5 bytes JMP 0000000100030804
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 00000000771dfc90 5 bytes JMP 0000000100030c0c
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771e0018 5 bytes JMP 0000000100030a08
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 00000000771e1900 5 bytes JMP 0000000100030e10
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000771fc45a 5 bytes JMP 00000001000301f8
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077201217 5 bytes JMP 00000001000303fc
.text C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe[2964] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000753ea30a 1 byte [62]