GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-02-04 22:12:50
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000005e ST350032 rev.SD15 465,76GB
Running: q455qqm7.exe; Driver: C:\Users\Mazi7\AppData\Local\Temp\ugloypod.sys


---- User code sections - GMER 2.1 ----

.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                0000000077351360 5 bytes JMP 0000000149fb0460
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                         00000000773513b0 5 bytes JMP 0000000149fb0450
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                         0000000077351510 5 bytes JMP 0000000149fb0370
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                              0000000077351560 5 bytes JMP 0000000149fb0470
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    0000000077351570 5 bytes JMP 0000000149fb03e0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                         0000000077351620 5 bytes JMP 0000000149fb0320
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                  0000000077351650 5 bytes JMP 0000000149fb03b0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                     0000000077351670 5 bytes JMP 0000000149fb0390
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                           00000000773516b0 5 bytes JMP 0000000149fb02e0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                         0000000077351730 5 bytes JMP 0000000149fb02d0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                       0000000077351750 5 bytes JMP 0000000149fb0310
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                        0000000077351790 5 bytes JMP 0000000149fb03c0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                     00000000773517e0 5 bytes JMP 0000000149fb03f0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                        0000000077351940 5 bytes JMP 0000000149fb0230
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                             0000000077351b00 5 bytes JMP 0000000149fb0480
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                            0000000077351b30 5 bytes JMP 0000000149fb03a0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                     0000000077351c10 5 bytes JMP 0000000149fb02f0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                  0000000077351c20 5 bytes JMP 0000000149fb0350
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                        0000000077351c80 5 bytes JMP 0000000149fb0290
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                     0000000077351d10 5 bytes JMP 0000000149fb02b0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                      0000000077351d30 5 bytes JMP 0000000149fb03d0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                         0000000077351d40 5 bytes JMP 0000000149fb0330
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                  0000000077351db0 5 bytes JMP 0000000149fb0410
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                     0000000077351de0 5 bytes JMP 0000000149fb0240
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                          00000000773520a0 5 bytes JMP 0000000149fb01e0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                     0000000077352160 5 bytes JMP 0000000149fb0250
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                     0000000077352190 5 bytes JMP 0000000149fb0490
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                            00000000773521a0 5 bytes JMP 0000000149fb04a0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                       00000000773521d0 5 bytes JMP 0000000149fb0300
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                    00000000773521e0 5 bytes JMP 0000000149fb0360
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                          0000000077352240 5 bytes JMP 0000000149fb02a0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                       0000000077352290 5 bytes JMP 0000000149fb02c0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                          00000000773522c0 5 bytes JMP 0000000149fb0380
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                           00000000773522d0 5 bytes JMP 0000000149fb0340
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                    00000000773525c0 5 bytes JMP 0000000149fb0440
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                   00000000773527c0 5 bytes JMP 0000000149fb0260
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                      00000000773527d0 5 bytes JMP 0000000149fb0270
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    00000000773527e0 5 bytes JMP 0000000149fb0400
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                00000000773529a0 5 bytes JMP 0000000149fb01f0
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                 00000000773529b0 5 bytes JMP 0000000149fb0210
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                      0000000077352a20 5 bytes JMP 0000000149fb0200
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                      0000000077352a80 5 bytes JMP 0000000149fb0420
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                       0000000077352a90 5 bytes JMP 0000000149fb0430
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                  0000000077352aa0 5 bytes JMP 0000000149fb0220
.text  C:\Windows\system32\csrss.exe[428] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                          0000000077352b80 5 bytes JMP 0000000149fb0280
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\wininit.exe[468] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                0000000077351360 5 bytes JMP 0000000149fb0460
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                         00000000773513b0 5 bytes JMP 0000000149fb0450
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                         0000000077351510 5 bytes JMP 0000000149fb0370
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                              0000000077351560 5 bytes JMP 0000000149fb0470
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    0000000077351570 5 bytes JMP 0000000149fb03e0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                         0000000077351620 5 bytes JMP 0000000149fb0320
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                  0000000077351650 5 bytes JMP 0000000149fb03b0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                     0000000077351670 5 bytes JMP 0000000149fb0390
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                           00000000773516b0 5 bytes JMP 0000000149fb02e0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                         0000000077351730 5 bytes JMP 0000000149fb02d0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                       0000000077351750 5 bytes JMP 0000000149fb0310
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                        0000000077351790 5 bytes JMP 0000000149fb03c0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                     00000000773517e0 5 bytes JMP 0000000149fb03f0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                        0000000077351940 5 bytes JMP 0000000149fb0230
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                             0000000077351b00 5 bytes JMP 0000000149fb0480
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                            0000000077351b30 5 bytes JMP 0000000149fb03a0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                     0000000077351c10 5 bytes JMP 0000000149fb02f0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                  0000000077351c20 5 bytes JMP 0000000149fb0350
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                        0000000077351c80 5 bytes JMP 0000000149fb0290
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                     0000000077351d10 5 bytes JMP 0000000149fb02b0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                      0000000077351d30 5 bytes JMP 0000000149fb03d0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                         0000000077351d40 5 bytes JMP 0000000149fb0330
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                  0000000077351db0 5 bytes JMP 0000000149fb0410
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                     0000000077351de0 5 bytes JMP 0000000149fb0240
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                          00000000773520a0 5 bytes JMP 0000000149fb01e0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                     0000000077352160 5 bytes JMP 0000000149fb0250
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                     0000000077352190 5 bytes JMP 0000000149fb0490
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                            00000000773521a0 5 bytes JMP 0000000149fb04a0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                       00000000773521d0 5 bytes JMP 0000000149fb0300
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                    00000000773521e0 5 bytes JMP 0000000149fb0360
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                          0000000077352240 5 bytes JMP 0000000149fb02a0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                       0000000077352290 5 bytes JMP 0000000149fb02c0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                          00000000773522c0 5 bytes JMP 0000000149fb0380
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                           00000000773522d0 5 bytes JMP 0000000149fb0340
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                    00000000773525c0 5 bytes JMP 0000000149fb0440
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                   00000000773527c0 5 bytes JMP 0000000149fb0260
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                      00000000773527d0 5 bytes JMP 0000000149fb0270
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    00000000773527e0 5 bytes JMP 0000000149fb0400
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                00000000773529a0 5 bytes JMP 0000000149fb01f0
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                 00000000773529b0 5 bytes JMP 0000000149fb0210
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                      0000000077352a20 5 bytes JMP 0000000149fb0200
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                      0000000077352a80 5 bytes JMP 0000000149fb0420
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                       0000000077352a90 5 bytes JMP 0000000149fb0430
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                  0000000077352aa0 5 bytes JMP 0000000149fb0220
.text  C:\Windows\system32\csrss.exe[488] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                          0000000077352b80 5 bytes JMP 0000000149fb0280
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\winlogon.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\services.exe[584] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                         00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                         0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                              0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                         0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                  0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                     0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                           00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                         0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                       0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                        0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                     00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                        0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                             0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                            0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                     0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                  0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                        0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                     0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                      0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                         0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                  0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                     0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                          00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                     0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                     0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                            00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                       00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                    00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                          0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                       0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                          00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                           00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                    00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                   00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                      00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                 00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                      0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                      0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                       0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                  0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\lsass.exe[592] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                          0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                  0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                           00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                           0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                                0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                      0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                           0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                    0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                       0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                             00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                           0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                         0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                          0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                       00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                          0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                               0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                              0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                       0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                    0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                          0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                       0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                        0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                           0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                    0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                       0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                            00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                       0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                       0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                              00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                         00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                      00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                            0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                         0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                            00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                             00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                      00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                     00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                        00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                      00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                  00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                   00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                        0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                        0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                         0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                    0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\lsm.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                            0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                               0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                        00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                        0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                             0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                   0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                        0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                 0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                    0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                          00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                        0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                      0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                       0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                    00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                       0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                            0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                           0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                    0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                 0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                       0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                    0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                     0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                        0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                 0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                    0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                         00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                    0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                    0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                           00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                      00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                   00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                         0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                      0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                         00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                          00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                   00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                  00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                     00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                   00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                               00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                     0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                     0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                      0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                 0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\nvvsvc.exe[784] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                         0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\svchost.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\System32\svchost.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\System32\svchost.exe[976] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 0000000100070460
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 0000000100070450
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 0000000100070370
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 0000000100070470
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000001000703e0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 0000000100070320
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000001000703b0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 0000000100070390
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000001000702e0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000001000702d0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 0000000100070310
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000001000703c0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000001000703f0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 0000000100070230
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 0000000100070480
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000001000703a0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000001000702f0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 0000000100070350
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 0000000100070290
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000001000702b0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000001000703d0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 0000000100070330
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 0000000100070410
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 0000000100070240
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000001000701e0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 0000000100070250
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 0000000100070490
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000001000704a0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 0000000100070300
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 0000000100070360
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000001000702a0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000001000702c0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 0000000100070380
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 0000000100070340
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 0000000100070440
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 0000000100070260
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 0000000100070270
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 0000000100070400
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000001000701f0
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 0000000100070210
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 0000000100070200
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 0000000100070420
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 0000000100070430
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 0000000100070220
.text  C:\Windows\system32\svchost.exe[324] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 0000000100070280
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\svchost.exe[1084] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                    0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                             00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                             0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                  0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                        0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                             0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                      0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                         0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                               00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                             0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                           0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                            0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                         00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                            0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                 0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                         0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                      0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                            0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                         0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                          0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                             0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                      0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                         0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                              00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                         0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                         0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                           00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                        00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                              0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                           0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                              00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                               00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                        00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                       00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                          00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                        00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                    00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                     00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                          0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                          0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                           0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                      0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1264] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                              0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\nvvsvc.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 0000000100070460
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 0000000100070450
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 0000000100070370
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 0000000100070470
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000001000703e0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 0000000100070320
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000001000703b0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 0000000100070390
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000001000702e0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000001000702d0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 0000000100070310
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000001000703c0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000001000703f0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 0000000100070230
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 0000000100070480
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000001000703a0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000001000702f0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 0000000100070350
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 0000000100070290
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000001000702b0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000001000703d0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 0000000100070330
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 0000000100070410
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 0000000100070240
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000001000701e0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 0000000100070250
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 0000000100070490
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000001000704a0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 0000000100070300
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 0000000100070360
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000001000702a0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000001000702c0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 0000000100070380
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 0000000100070340
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 0000000100070440
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 0000000100070260
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 0000000100070270
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 0000000100070400
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000001000701f0
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 0000000100070210
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 0000000100070200
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 0000000100070420
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 0000000100070430
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 0000000100070220
.text  C:\Windows\System32\spoolsv.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 0000000100070280
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\svchost.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 0000000100070460
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 0000000100070450
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 0000000100070370
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 0000000100070470
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000001000703e0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 0000000100070320
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000001000703b0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 0000000100070390
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000001000702e0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000001000702d0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 0000000100070310
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000001000703c0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000001000703f0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 0000000100070230
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 0000000100070480
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000001000703a0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000001000702f0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 0000000100070350
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 0000000100070290
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000001000702b0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000001000703d0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 0000000100070330
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 0000000100070410
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 0000000100070240
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000001000701e0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 0000000100070250
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 0000000100070490
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000001000704a0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 0000000100070300
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 0000000100070360
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000001000702a0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000001000702c0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 0000000100070380
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 0000000100070340
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 0000000100070440
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 0000000100070260
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 0000000100070270
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 0000000100070400
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000001000701f0
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 0000000100070210
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 0000000100070200
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 0000000100070420
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 0000000100070430
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 0000000100070220
.text  C:\Windows\system32\svchost.exe[1644] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 0000000100070280
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort      0000000077351360 5 bytes JMP 0000000100070460
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject               00000000773513b0 5 bytes JMP 0000000100070450
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess               0000000077351510 5 bytes JMP 0000000100070370
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx    0000000077351560 5 bytes JMP 0000000100070470
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess          0000000077351570 5 bytes JMP 00000001000703e0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection               0000000077351620 5 bytes JMP 0000000100070320
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory        0000000077351650 5 bytes JMP 00000001000703b0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject           0000000077351670 5 bytes JMP 0000000100070390
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                 00000000773516b0 5 bytes JMP 00000001000702e0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent               0000000077351730 5 bytes JMP 00000001000702d0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection             0000000077351750 5 bytes JMP 0000000100070310
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread              0000000077351790 5 bytes JMP 00000001000703c0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread           00000000773517e0 5 bytes JMP 00000001000703f0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry              0000000077351940 5 bytes JMP 0000000100070230
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort   0000000077351b00 5 bytes JMP 0000000100070480
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject  0000000077351b30 5 bytes JMP 00000001000703a0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair           0000000077351c10 5 bytes JMP 00000001000702f0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion        0000000077351c20 5 bytes JMP 0000000100070350
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant              0000000077351c80 5 bytes JMP 0000000100070290
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore           0000000077351d10 5 bytes JMP 00000001000702b0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx            0000000077351d30 5 bytes JMP 00000001000703d0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer               0000000077351d40 5 bytes JMP 0000000100070330
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess        0000000077351db0 5 bytes JMP 0000000100070410
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry           0000000077351de0 5 bytes JMP 0000000100070240
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                00000000773520a0 5 bytes JMP 00000001000701e0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry           0000000077352160 5 bytes JMP 0000000100070250
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey           0000000077352190 5 bytes JMP 0000000100070490
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys  00000000773521a0 5 bytes JMP 00000001000704a0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair             00000000773521d0 5 bytes JMP 0000000100070300
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion          00000000773521e0 5 bytes JMP 0000000100070360
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                0000000077352240 5 bytes JMP 00000001000702a0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore             0000000077352290 5 bytes JMP 00000001000702c0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                00000000773522c0 5 bytes JMP 0000000100070380
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                 00000000773522d0 5 bytes JMP 0000000100070340
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx          00000000773525c0 5 bytes JMP 0000000100070440
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder         00000000773527c0 5 bytes JMP 0000000100070260
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions            00000000773527d0 5 bytes JMP 0000000100070270
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread          00000000773527e0 5 bytes JMP 0000000100070400
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation      00000000773529a0 5 bytes JMP 00000001000701f0
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState       00000000773529b0 5 bytes JMP 0000000100070210
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem            0000000077352a20 5 bytes JMP 0000000100070200
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess            0000000077352a80 5 bytes JMP 0000000100070420
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread             0000000077352a90 5 bytes JMP 0000000100070430
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl        0000000077352aa0 5 bytes JMP 0000000100070220
.text  C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1668] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                0000000077352b80 5 bytes JMP 0000000100070280
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1832] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\SysWOW64\PnkBstrA.exe[1892] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322                                                                0000000074971a22 2 bytes [97, 74]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[1892] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496                                                                0000000074971ad0 2 bytes [97, 74]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[1892] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552                                                                0000000074971b08 2 bytes [97, 74]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[1892] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730                                                                0000000074971bba 2 bytes [97, 74]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[1892] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762                                                                0000000074971bda 2 bytes [97, 74]
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort               0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                        00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                        0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx             0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                   0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                        0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                 0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                    0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                          00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                        0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                      0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                       0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                    00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                       0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort            0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject           0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                    0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                 0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                       0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                    0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                     0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                        0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                 0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                    0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                         00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                    0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                    0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys           00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                      00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                   00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                         0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                      0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                         00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                          00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                   00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                  00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                     00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                   00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation               00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                     0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                     0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                      0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                 0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe[2020] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                         0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                   0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                            00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                            0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                 0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                       0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                            0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                     0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                        0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                              00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                            0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                          0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                           0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                        00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                           0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject               0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                        0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                     0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                           0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                        0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                         0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                            0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                     0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                        0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                             00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                        0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                        0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys               00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                          00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                       00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                             0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                          0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                             00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                              00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                       00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                      00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                         00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                       00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                   00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                    00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                         0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                         0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                          0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                     0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe[1064] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                             0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1448] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                              0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                       00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                       0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                            0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                  0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                       0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                   0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                         00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                       0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                     0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                      0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                   00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                      0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                           0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                          0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                   0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                      0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                   0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                    0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                       0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                   0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                        00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                   0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                   0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                          00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                     00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                  00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                        0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                     0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                        00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                         00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                  00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                 00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                    00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                  00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                              00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                               00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                    0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                    0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                     0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[2384] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                        0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                       0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                     0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                           0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                         0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                            0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                  00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                              0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                               0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                            00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                               0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                    0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                   0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                            0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                         0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                               0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                            0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                             0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                         0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                            0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                 00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                            0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                            0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                   00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                              00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                           00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                 0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                              0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                 00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                  00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                           00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                          00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                             00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                           00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                       00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                        00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                             0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                             0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                              0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                         0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\wbem\wmiprvse.exe[2540] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                 0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                            0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                     00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                     0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                          0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                     0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                              0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                 0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                       00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                     0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                   0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                    0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                 00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                    0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                         0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                        0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                 0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                              0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                    0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                 0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                  0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                     0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                              0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                 0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                      00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                 0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                 0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                        00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                   00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                      0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                   0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                      00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                       00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                               00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                  00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                            00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                             00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                  0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                  0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                   0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                              0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\taskhost.exe[2944] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                      0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2052] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\conhost.exe[2616] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                 0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                          00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                          0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                               0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                     0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                          0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                   0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                      0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                            00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                          0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                        0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                         0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                      00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                         0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                              0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                             0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                      0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                   0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                         0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                      0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                       0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                          0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                   0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                      0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                           00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                      0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                      0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                             00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                        00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                     00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                           0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                        0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                           00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                            00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                     00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                    00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                       00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                     00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                 00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                  00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                       0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                       0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                        0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                   0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\Dwm.exe[3016] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                           0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                     0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                              00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                              0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                                   0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                         0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                              0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                       0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                          0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                                00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                              0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                            0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                             0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                          00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                             0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                  0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                                 0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                          0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                                       0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                             0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                          0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                           0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                              0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                                       0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                          0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                               00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                          0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                          0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                                 00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                            00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                         00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                               0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                            0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                               00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                                00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                         00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                        00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                           00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                         00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                     00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                                      00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                           0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                           0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                            0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                       0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\Explorer.EXE[1808] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                               0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\kernel32.dll!CreateFileW                                                            0000000076b73f1c 5 bytes JMP 000000016ac875f0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!SetWindowPos                                                             00000000769ccdb4 5 bytes JMP 000000016ac86ad0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!ShowWindow                                                               00000000769d0dbe 5 bytes JMP 000000016ac868b0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!SetFocus                                                                 00000000769d1b99 5 bytes JMP 000000016ac869c0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!SetForegroundWindow                                                      00000000769d1d34 5 bytes JMP 000000016ac864d0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!SetActiveWindow                                                          00000000769d2890 5 bytes JMP 000000016ac86be0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!BringWindowToTop                                                         00000000769d7ba7 5 bytes JMP 000000016ac865e0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!SwitchToThisWindow                                                       0000000076a0908c 5 bytes JMP 000000016ac866f0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\USER32.dll!ShowWindowAsync                                                          0000000076a27f27 5 bytes JMP 000000016ac867a0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\ole32.dll!DoDragDrop                                                                0000000075bda827 5 bytes JMP 000000016ac863e0
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                 0000000075ac1465 2 bytes [AC, 75]
.text  C:\Program Files (x86)\Origin\Origin.exe[3240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                0000000075ac14bb 2 bytes [AC, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                      0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                               00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                               0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                    0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                          0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                               0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                        0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                           0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                 00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                               0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                             0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                              0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                           00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                              0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                   0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                  0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                           0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                        0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                              0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                           0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                            0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                               0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                        0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                           0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                           0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                           0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                  00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                             00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                          00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                             0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                 00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                          00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                         00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                            00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                          00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                      00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                       00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                            0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                            0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                             0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                        0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3280] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[3340] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                                   0000000076b78791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[3340] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                        0000000075ac1465 2 bytes [AC, 75]
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[3340] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                       0000000075ac14bb 2 bytes [AC, 75]
.text  ...                                                                                                                                                    * 2
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                       0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                     0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                           0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                         0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                            0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                  00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                              0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                               0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                            00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                               0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                    0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                   0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                            0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                         0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                               0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                            0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                             0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                         0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                            0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                 00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                            0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                            0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                   00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                              00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                           00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                 0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                              0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                 00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                  00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                           00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                          00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                             00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                           00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                       00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                        00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                             0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                             0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                              0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                         0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\system32\SearchIndexer.exe[3632] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                 0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\System32\svchost.exe[3152] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 00000000774b0460
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 00000000774b0450
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 00000000774b0370
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 00000000774b0470
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000000774b03e0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 00000000774b0320
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000000774b03b0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 00000000774b0390
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000000774b02e0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000000774b02d0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 00000000774b0310
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000000774b03c0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000000774b03f0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 00000000774b0230
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 00000000774b0480
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000000774b03a0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000000774b02f0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 00000000774b0350
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 00000000774b0290
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000000774b02b0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000000774b03d0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 00000000774b0330
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 00000000774b0410
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 00000000774b0240
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000000774b01e0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 00000000774b0250
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 00000000774b0490
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000000774b04a0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 00000000774b0300
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 00000000774b0360
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000000774b02a0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000000774b02c0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 00000000774b0380
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 00000000774b0340
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 00000000774b0440
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 00000000774b0260
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 00000000774b0270
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 00000000774b0400
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000000774b01f0
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 00000000774b0210
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 00000000774b0200
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 00000000774b0420
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 00000000774b0430
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 00000000774b0220
.text  C:\Windows\System32\svchost.exe[1924] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 00000000774b0280
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                             0000000077351360 5 bytes JMP 0000000100070460
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                                                                      00000000773513b0 5 bytes JMP 0000000100070450
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                                                                      0000000077351510 5 bytes JMP 0000000100070370
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                           0000000077351560 5 bytes JMP 0000000100070470
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                 0000000077351570 5 bytes JMP 00000001000703e0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                      0000000077351620 5 bytes JMP 0000000100070320
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                               0000000077351650 5 bytes JMP 00000001000703b0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                                                                  0000000077351670 5 bytes JMP 0000000100070390
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                                                                        00000000773516b0 5 bytes JMP 00000001000702e0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                      0000000077351730 5 bytes JMP 00000001000702d0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                    0000000077351750 5 bytes JMP 0000000100070310
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                     0000000077351790 5 bytes JMP 00000001000703c0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                  00000000773517e0 5 bytes JMP 00000001000703f0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                                                                     0000000077351940 5 bytes JMP 0000000100070230
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                          0000000077351b00 5 bytes JMP 0000000100070480
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject                                                         0000000077351b30 5 bytes JMP 00000001000703a0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                  0000000077351c10 5 bytes JMP 00000001000702f0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                                                               0000000077351c20 5 bytes JMP 0000000100070350
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                     0000000077351c80 5 bytes JMP 0000000100070290
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                  0000000077351d10 5 bytes JMP 00000001000702b0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                   0000000077351d30 5 bytes JMP 00000001000703d0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                                                                      0000000077351d40 5 bytes JMP 0000000100070330
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                                                               0000000077351db0 5 bytes JMP 0000000100070410
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                                                                  0000000077351de0 5 bytes JMP 0000000100070240
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                       00000000773520a0 5 bytes JMP 00000001000701e0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                                                                  0000000077352160 5 bytes JMP 0000000100070250
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                                                                  0000000077352190 5 bytes JMP 0000000100070490
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys                                                         00000000773521a0 5 bytes JMP 00000001000704a0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                                                                    00000000773521d0 5 bytes JMP 0000000100070300
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                                                                 00000000773521e0 5 bytes JMP 0000000100070360
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                                                                       0000000077352240 5 bytes JMP 00000001000702a0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                                                                    0000000077352290 5 bytes JMP 00000001000702c0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                                                                       00000000773522c0 5 bytes JMP 0000000100070380
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                                                                        00000000773522d0 5 bytes JMP 0000000100070340
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                                                                 00000000773525c0 5 bytes JMP 0000000100070440
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                                                                00000000773527c0 5 bytes JMP 0000000100070260
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                                                                   00000000773527d0 5 bytes JMP 0000000100070270
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                 00000000773527e0 5 bytes JMP 0000000100070400
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                             00000000773529a0 5 bytes JMP 00000001000701f0
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                                                              00000000773529b0 5 bytes JMP 0000000100070210
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                   0000000077352a20 5 bytes JMP 0000000100070200
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                                                                   0000000077352a80 5 bytes JMP 0000000100070420
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                                                                    0000000077352a90 5 bytes JMP 0000000100070430
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                               0000000077352aa0 5 bytes JMP 0000000100070220
.text  C:\Windows\system32\AUDIODG.EXE[4648] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                                                                       0000000077352b80 5 bytes JMP 0000000100070280
.text  C:\Users\Mazi7\Downloads\OTL_[www.programosy.pl].exe[4508] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69                                     0000000075ac1465 2 bytes [AC, 75]
.text  C:\Users\Mazi7\Downloads\OTL_[www.programosy.pl].exe[4508] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155                                    0000000075ac14bb 2 bytes [AC, 75]
.text  ...                                                                                                                                                    * 2

---- EOF - GMER 2.1 ----
