GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-11-28 23:23:58
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000AAKX-00ERMA0 rev.15.01H15 465,76GB
Running: mwee7ntc.exe; Driver: C:\Users\PANWAS~1\AppData\Local\Temp\pxldqpoc.sys


---- User code sections - GMER 2.2 ----

.text   C:\Windows\system32\csrss.exe[424] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                                                             0000000076e8bde0 8 bytes JMP 000000006fff00d8
.text   C:\Windows\system32\csrss.exe[424] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                                                                           0000000076e8bfe0 8 bytes JMP 000000006fff0110
.text   C:\Windows\system32\csrss.exe[424] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                          0000000076e8c580 8 bytes JMP 000000006fff0148
.text   C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort                                                                                                             0000000076e8bde0 8 bytes JMP 000000006fff00d8
.text   C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx                                                                                                           0000000076e8bfe0 8 bytes JMP 000000006fff0110
.text   C:\Windows\system32\csrss.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                          0000000076e8c580 8 bytes JMP 000000006fff0148
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                  0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                       0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                        0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                          0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                        0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                          0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\RPCRT4.dll!RpcServerRegisterIfEx                                                                                                          000007fefddf2930 6 bytes JMP 0
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!RegisterRawInputDevices                                                                                                        0000000076c26e80 6 bytes {JMP QWORD [RIP+0x98191b0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SystemParametersInfoA                                                                                                          0000000076c280c4 6 bytes {JMP QWORD [RIP+0x98f7f6c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetParent                                                                                                                      0000000076c28460 6 bytes {JMP QWORD [RIP+0x9837bd0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetWindowLongA                                                                                                                 0000000076c29b00 6 bytes {JMP QWORD [RIP+0x9596530]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!PostMessageA                                                                                                                   0000000076c2a350 6 bytes {JMP QWORD [RIP+0x95d5ce0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!EnableWindow                                                                                                                   0000000076c2aa00 6 bytes {JMP QWORD [RIP+0x9935630]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!MoveWindow                                                                                                                     0000000076c2aa30 6 bytes {JMP QWORD [RIP+0x9855600]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!GetAsyncKeyState                                                                                                               0000000076c2c63c 6 bytes {JMP QWORD [RIP+0x97f39f4]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!RegisterHotKey                                                                                                                 0000000076c2cc90 6 bytes {JMP QWORD [RIP+0x98d33a0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!PostThreadMessageA                                                                                                             0000000076c2d220 6 bytes {JMP QWORD [RIP+0x9612e10]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageA                                                                                                                   0000000076c2d2a8 6 bytes {JMP QWORD [RIP+0x9652d88]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendNotifyMessageW                                                                                                             0000000076c2dbd0 6 bytes {JMP QWORD [RIP+0x9732460]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SystemParametersInfoW                                                                                                          0000000076c2f4a0 6 bytes {JMP QWORD [RIP+0x9910b90]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetWindowsHookExW                                                                                                              0000000076c2f814 6 bytes {JMP QWORD [RIP+0x955081c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageTimeoutW                                                                                                            0000000076c2fa60 6 bytes {JMP QWORD [RIP+0x96b05d0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!PostThreadMessageW                                                                                                             0000000076c30b14 6 bytes {JMP QWORD [RIP+0x962f51c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetWindowLongW                                                                                                                 0000000076c33350 6 bytes {JMP QWORD [RIP+0x95acce0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetWinEventHook + 1                                                                                                            0000000076c34cfd 5 bytes {JMP QWORD [RIP+0x956b334]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!GetKeyState                                                                                                                    0000000076c34fb0 6 bytes {JMP QWORD [RIP+0x97cb080]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageCallbackW                                                                                                           0000000076c353f4 6 bytes {JMP QWORD [RIP+0x96eac3c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageW                                                                                                                   0000000076c36b44 6 bytes {JMP QWORD [RIP+0x96694ec]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!PostMessageW                                                                                                                   0000000076c37714 6 bytes {JMP QWORD [RIP+0x95e891c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendDlgItemMessageW                                                                                                            0000000076c3dd9c 6 bytes {JMP QWORD [RIP+0x9762294]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!GetClipboardData                                                                                                               0000000076c3e854 6 bytes {JMP QWORD [RIP+0x98a17dc]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetClipboardViewer                                                                                                             0000000076c3f770 6 bytes {JMP QWORD [RIP+0x98608c0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendNotifyMessageA                                                                                                             0000000076c428b4 6 bytes {JMP QWORD [RIP+0x96fd77c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!mouse_event                                                                                                                    0000000076c43854 6 bytes {JMP QWORD [RIP+0x94fc7dc]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!GetKeyboardState                                                                                                               0000000076c489c0 6 bytes {JMP QWORD [RIP+0x9797670]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageTimeoutA                                                                                                            0000000076c48b88 6 bytes {JMP QWORD [RIP+0x96774a8]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SetWindowsHookExA                                                                                                              0000000076c48bd0 6 bytes {JMP QWORD [RIP+0x9517460]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendInput                                                                                                                      0000000076c48c90 6 bytes {JMP QWORD [RIP+0x97773a0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!BlockInput                                                                                                                     0000000076c4ad10 6 bytes {JMP QWORD [RIP+0x9875320]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!ExitWindowsEx                                                                                                                  0000000076c71514 6 bytes {JMP QWORD [RIP+0x990eb1c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!keybd_event                                                                                                                    0000000076c945f0 6 bytes {JMP QWORD [RIP+0x948ba40]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendDlgItemMessageA                                                                                                            0000000076c9cc6c 6 bytes {JMP QWORD [RIP+0x96e33c4]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\USER32.dll!SendMessageCallbackA                                                                                                           0000000076c9df68 6 bytes {JMP QWORD [RIP+0x96620c8]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                        000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xfdd50]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                          000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x11dca0]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                         000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x138abc]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                       000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xb7e4c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                       000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x9781c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                        000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xd72c4]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                      000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x17458c]}
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                          000007fefdfec7a0 6 bytes JMP 61006e
.text   C:\Windows\system32\services.exe[612] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes JMP 80140001
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                       0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                            0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                            0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                                 0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                         0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                      0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                            0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                      0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                    0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                     0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                  0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                       0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                  0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                   0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                          0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                      0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                  0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                     0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                       0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                  0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                         0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                   0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                       0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                              0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                             0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                   0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                               0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                     0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                          0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                           0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                             0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                           0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                             0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                  000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                           000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                             000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                            000007fefdfe7574 6 bytes JMP 0
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                          000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                          000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                           000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                         000007fefdfebaa4 6 bytes JMP 0
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                             000007fefdfec7a0 6 bytes JMP 360032
.text   C:\Windows\system32\lsass.exe[620] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                   000007fefd1b6d10 6 bytes JMP 0
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                         0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                              0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                              0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                                   0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                           0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                        0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                              0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                        0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                      0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                       0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                    0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                         0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                    0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                     0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                            0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                        0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                    0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                       0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                         0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                    0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                           0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                     0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                         0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                                0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                               0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                     0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                                 0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                       0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                            0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                             0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                               0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                             0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                               0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                    000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                             000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                               000007fefdfe2390 6 bytes JMP 10008
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                              000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                            000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                            000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                             000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                           000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                               000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\system32\lsm.exe[628] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                     000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\RPCRT4.dll!RpcServerRegisterIfEx                                                                                                           000007fefddf2930 6 bytes {JMP QWORD [RIP+0x25d700]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xfdd50]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x11dca0]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x138abc]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xb7e4c]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x9781c]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xd72c4]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x17458c]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x153890]}
.text   C:\Windows\system32\svchost.exe[724] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                          000000007703f9f0 3 bytes JMP 71af000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4                                                                                      000000007703f9f4 2 bytes JMP 71af000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess                                                                          000000007703fb38 3 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess + 4                                                                      000000007703fb3c 2 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                               000000007703fcc0 3 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4                                                                           000000007703fcc4 2 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                       000000007703fd74 3 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4                                                                                   000000007703fd78 2 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                                    000000007703fdd8 3 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4                                                                                000000007703fddc 2 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                          000000007703fed0 3 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4                                                                      000000007703fed4 2 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent                                                                                    000000007703ff84 3 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent + 4                                                                                000000007703ff88 2 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                                  000000007703ffb4 3 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4                                                                              000000007703ffb8 2 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                                   0000000077040014 3 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4                                                                               0000000077040018 2 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                                0000000077040094 3 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4                                                                            0000000077040098 2 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                     00000000770400c4 3 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4                                                                                 00000000770400c8 2 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                                00000000770403c8 3 bytes JMP 70b5000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4                                                                            00000000770403cc 2 bytes JMP 70b5000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort                                                                                 00000000770403e0 3 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort + 4                                                                             00000000770403e4 2 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                        0000000077040560 3 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4                                                                    0000000077040564 2 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                                    00000000770406a4 3 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4                                                                                00000000770406a8 2 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair                                                                                0000000077040704 3 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair + 4                                                                            0000000077040708 2 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                                   00000000770407ac 3 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant + 4                                                                               00000000770407b0 2 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort                                                                                     00000000770407f4 3 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort + 4                                                                                 00000000770407f8 2 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore                                                                                0000000077040884 3 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore + 4                                                                            0000000077040888 2 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                       000000007704089c 3 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4                                                                   00000000770408a0 2 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                                 00000000770408b4 3 bytes JMP 70b8000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4                                                                             00000000770408b8 2 bytes JMP 70b8000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                                     0000000077040e04 3 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4                                                                                 0000000077040e08 2 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                            0000000077040ee8 3 bytes JMP 70be000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4                                                                        0000000077040eec 2 bytes JMP 70be000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                           0000000077041bf4 3 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4                                                                       0000000077041bf8 2 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                                 0000000077041cc4 3 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4                                                                             0000000077041cc8 2 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                             0000000077041d9c 3 bytes JMP 70df000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4                                                                         0000000077041da0 2 bytes JMP 70df000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                                     000000007705d2f6 6 bytes JMP 71a8000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW                                                                        0000000076213bbb 3 bytes JMP 719c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW + 4                                                                    0000000076213bbf 2 bytes JMP 719c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressW                                                                         0000000076219abc 6 bytes JMP 7187000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!CopyFileExW                                                                                   0000000076223b7a 6 bytes JMP 717e000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressA                                                                         000000007622cd11 6 bytes JMP 718a000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedA                                                                           000000007627ddde 6 bytes JMP 7184000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW                                                                           000000007627de81 3 bytes JMP 7181000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW + 4                                                                       000000007627de85 2 bytes JMP 7181000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                                00000000769af8a7 6 bytes JMP 719f000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 559                                                                        00000000769b2e0b 4 bytes CALL 71ac0000
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetWindowLongW                                                                                  0000000075638332 6 bytes JMP 7157000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                              0000000075638bff 6 bytes JMP 714b000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                           00000000756390d3 6 bytes JMP 7106000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                                    0000000075639679 6 bytes JMP 7145000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                             00000000756397d2 6 bytes JMP 713f000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                                 000000007563ee21 6 bytes JMP 715d000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                                  000000007563efe1 3 bytes JMP 710c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!RegisterHotKey + 4                                                                              000000007563efe5 2 bytes JMP 710c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                                    00000000756412bd 6 bytes JMP 7151000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                     0000000075642797 6 bytes JMP 7124000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                                      0000000075643ef0 3 bytes JMP 7118000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!MoveWindow + 4                                                                                  0000000075643ef4 2 bytes JMP 7118000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetParent                                                                                       00000000756445cc 3 bytes JMP 711b000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetParent + 4                                                                                   00000000756445d0 2 bytes JMP 711b000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                    000000007564460c 6 bytes JMP 7103000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                0000000075644713 6 bytes JMP 7121000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                                00000000756447e5 3 bytes JMP 7127000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!GetKeyboardState + 4                                                                            00000000756447e9 2 bytes JMP 7127000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                                    0000000075644bbc 6 bytes JMP 7154000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                              0000000075644d1d 6 bytes JMP 714e000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetWindowLongA                                                                                  00000000756471e0 6 bytes JMP 715a000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                                    00000000756471fe 6 bytes JMP 7148000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                           0000000075647d59 6 bytes JMP 7109000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                               00000000756481f5 6 bytes JMP 7160000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                              000000007564825a 6 bytes JMP 7133000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                            00000000756482d2 6 bytes JMP 7139000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                             0000000075648411 6 bytes JMP 7142000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                               0000000075648f4c 6 bytes JMP 7163000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                              000000007564cc1e 3 bytes JMP 7115000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SetClipboardViewer + 4                                                                          000000007564cc22 2 bytes JMP 7115000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                             000000007565a072 6 bytes JMP 7130000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                             000000007565dc05 6 bytes JMP 712d000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendInput                                                                                       000000007565ff3a 3 bytes JMP 712a000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendInput + 4                                                                                   000000007565ff3e 2 bytes JMP 712a000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                                0000000075679fa4 6 bytes JMP 710f000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                                   0000000075681533 6 bytes JMP 7100000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!mouse_event                                                                                     000000007569030f 6 bytes JMP 7166000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                     0000000075690353 6 bytes JMP 7169000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                            0000000075696d94 6 bytes JMP 713c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                              0000000075696df5 6 bytes JMP 7136000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!BlockInput                                                                                      0000000075697e6f 3 bytes JMP 7112000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!BlockInput + 4                                                                                  0000000075697e73 2 bytes JMP 7112000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                         0000000075698983 3 bytes JMP 711e000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices + 4                                                                     0000000075698987 2 bytes JMP 711e000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                         0000000075d658b3 6 bytes JMP 718d000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                           0000000075d65ea5 6 bytes JMP 7175000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                        0000000075d67bcc 6 bytes JMP 7196000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                         0000000075d6b98a 6 bytes JMP 7190000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                       0000000075d6bd7d 6 bytes JMP 716c000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                          0000000075d6cf11 6 bytes JMP 7172000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                        0000000075d6e935 6 bytes JMP 7193000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                           0000000075d94aaa 6 bytes JMP 716f000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\SHELL32.dll!SHFileOperationW                                                                               0000000074a29670 6 bytes JMP 7178000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\SHELL32.dll!SHFileOperation                                                                                0000000074c2c509 6 bytes JMP 717b000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                                 0000000075c39cbb 6 bytes JMP 7199000a
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                        0000000076751401 2 bytes JMP 7622b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                          0000000076751419 2 bytes JMP 7622b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                        0000000076751431 2 bytes JMP 762a9149 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                        000000007675144a 2 bytes CALL 76204885 C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                                 * 9
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                           00000000767514dd 2 bytes JMP 762a8a42 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                    00000000767514f5 2 bytes JMP 762a8c18 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                           000000007675150d 2 bytes JMP 762a8938 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                    0000000076751525 2 bytes JMP 762a8d02 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                          000000007675153d 2 bytes JMP 7621fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                               0000000076751555 2 bytes JMP 76226907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                        000000007675156d 2 bytes JMP 762a9201 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                          0000000076751585 2 bytes JMP 762a8d62 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                             000000007675159d 2 bytes JMP 762a88fc C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                          00000000767515b5 2 bytes JMP 7621fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                        00000000767515cd 2 bytes JMP 7622b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                    00000000767516b2 2 bytes JMP 762a90c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe[792] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                    00000000767516bd 2 bytes JMP 762a8891 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                      0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                           0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                           0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                                0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                        0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                     0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                           0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                     0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                   0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                    0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                 0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                      0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                 0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                  0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                         0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                     0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                 0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                    0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                      0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                 0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                        0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                  0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                      0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                             0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                            0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                  0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                              0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                    0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                         0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                          0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                            0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                          0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                            0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                 000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                          000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0x2cdd50]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                            000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x2edca0]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                           000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x308abc]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                         000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0x287e4c]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                         000007fefdfe8814 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                          000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0x2a72c4]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                        000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x34458c]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                            000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x323890]}
.text   C:\Windows\system32\nvvsvc.exe[816] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                  000007fefd1b6d10 6 bytes JMP 0
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                      000000007703f9f0 3 bytes JMP 71af000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4                                                                                  000000007703f9f4 2 bytes JMP 71af000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess                                                                      000000007703fb38 3 bytes JMP 70c1000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess + 4                                                                  000000007703fb3c 2 bytes JMP 70c1000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                           000000007703fcc0 3 bytes JMP 70e2000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4                                                                       000000007703fcc4 2 bytes JMP 70e2000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                   000000007703fd74 3 bytes JMP 70cd000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4                                                                               000000007703fd78 2 bytes JMP 70cd000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                                000000007703fdd8 3 bytes JMP 70d3000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4                                                                            000000007703fddc 2 bytes JMP 70d3000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                      000000007703fed0 3 bytes JMP 70ca000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4                                                                  000000007703fed4 2 bytes JMP 70ca000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent                                                                                000000007703ff84 3 bytes JMP 70fa000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent + 4                                                                            000000007703ff88 2 bytes JMP 70fa000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                              000000007703ffb4 3 bytes JMP 70d6000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4                                                                          000000007703ffb8 2 bytes JMP 70d6000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                               0000000077040014 3 bytes JMP 70ee000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4                                                                           0000000077040018 2 bytes JMP 70ee000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                            0000000077040094 3 bytes JMP 70eb000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4                                                                        0000000077040098 2 bytes JMP 70eb000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                 00000000770400c4 3 bytes JMP 70d0000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4                                                                             00000000770400c8 2 bytes JMP 70d0000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                            00000000770403c8 3 bytes JMP 70bb000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4                                                                        00000000770403cc 2 bytes JMP 70bb000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort                                                                             00000000770403e0 3 bytes JMP 7100000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort + 4                                                                         00000000770403e4 2 bytes JMP 7100000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                    0000000077040560 3 bytes JMP 7103000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4                                                                0000000077040564 2 bytes JMP 7103000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                                00000000770406a4 3 bytes JMP 70df000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4                                                                            00000000770406a8 2 bytes JMP 70df000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair                                                                            0000000077040704 3 bytes JMP 70f7000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair + 4                                                                        0000000077040708 2 bytes JMP 70f7000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                               00000000770407ac 3 bytes JMP 70fd000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant + 4                                                                           00000000770407b0 2 bytes JMP 70fd000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort                                                                                 00000000770407f4 3 bytes JMP 70f1000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort + 4                                                                             00000000770407f8 2 bytes JMP 70f1000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore                                                                            0000000077040884 3 bytes JMP 70f4000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore + 4                                                                        0000000077040888 2 bytes JMP 70f4000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                   000000007704089c 3 bytes JMP 70c7000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4                                                               00000000770408a0 2 bytes JMP 70c7000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                             00000000770408b4 3 bytes JMP 70be000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4                                                                         00000000770408b8 2 bytes JMP 70be000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                                 0000000077040e04 3 bytes JMP 70dc000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4                                                                             0000000077040e08 2 bytes JMP 70dc000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                        0000000077040ee8 3 bytes JMP 70c4000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4                                                                    0000000077040eec 2 bytes JMP 70c4000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                       0000000077041bf4 3 bytes JMP 70d9000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4                                                                   0000000077041bf8 2 bytes JMP 70d9000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                             0000000077041cc4 3 bytes JMP 70e8000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4                                                                         0000000077041cc8 2 bytes JMP 70e8000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                         0000000077041d9c 3 bytes JMP 70e5000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4                                                                     0000000077041da0 2 bytes JMP 70e5000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                                 000000007705d2f6 6 bytes JMP 71a8000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW                                                                    0000000076213bbb 3 bytes JMP 719c000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW + 4                                                                0000000076213bbf 2 bytes JMP 719c000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressW                                                                     0000000076219abc 6 bytes JMP 7187000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!CopyFileExW                                                                               0000000076223b7a 6 bytes JMP 717e000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressA                                                                     000000007622cd11 6 bytes JMP 718a000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedA                                                                       000000007627ddde 6 bytes JMP 7184000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW                                                                       000000007627de81 3 bytes JMP 7181000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW + 4                                                                   000000007627de85 2 bytes JMP 7181000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                            00000000769af8a7 6 bytes JMP 719f000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 559                                                                    00000000769b2e0b 4 bytes CALL 71ac0000
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                     0000000075d658b3 6 bytes JMP 718d000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                       0000000075d65ea5 6 bytes JMP 717b000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                    0000000075d67bcc 6 bytes JMP 7196000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                     0000000075d6b98a 6 bytes JMP 7190000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                   0000000075d6bd7d 6 bytes JMP 7172000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                      0000000075d6cf11 6 bytes JMP 7178000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                    0000000075d6e935 6 bytes JMP 7193000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                       0000000075d94aaa 6 bytes JMP 7175000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetWindowLongW                                                                              0000000075638332 6 bytes JMP 715d000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                          0000000075638bff 6 bytes JMP 7151000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                       00000000756390d3 6 bytes JMP 710c000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                                0000000075639679 6 bytes JMP 714b000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                         00000000756397d2 6 bytes JMP 7145000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                             000000007563ee21 6 bytes JMP 7163000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                              000000007563efe1 3 bytes JMP 7112000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!RegisterHotKey + 4                                                                          000000007563efe5 2 bytes JMP 7112000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                                00000000756412bd 6 bytes JMP 7157000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                 0000000075642797 6 bytes JMP 712a000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                                  0000000075643ef0 3 bytes JMP 711e000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!MoveWindow + 4                                                                              0000000075643ef4 2 bytes JMP 711e000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetParent                                                                                   00000000756445cc 3 bytes JMP 7121000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetParent + 4                                                                               00000000756445d0 2 bytes JMP 7121000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                000000007564460c 6 bytes JMP 7109000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                            0000000075644713 6 bytes JMP 7127000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                            00000000756447e5 3 bytes JMP 712d000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!GetKeyboardState + 4                                                                        00000000756447e9 2 bytes JMP 712d000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                                0000000075644bbc 6 bytes JMP 715a000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                          0000000075644d1d 6 bytes JMP 7154000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetWindowLongA                                                                              00000000756471e0 6 bytes JMP 7160000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                                00000000756471fe 6 bytes JMP 714e000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                       0000000075647d59 6 bytes JMP 710f000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                           00000000756481f5 6 bytes JMP 7166000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                          000000007564825a 6 bytes JMP 7139000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                        00000000756482d2 6 bytes JMP 713f000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                         0000000075648411 6 bytes JMP 7148000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                           0000000075648f4c 6 bytes JMP 7169000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                          000000007564cc1e 3 bytes JMP 711b000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SetClipboardViewer + 4                                                                      000000007564cc22 2 bytes JMP 711b000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                         000000007565a072 6 bytes JMP 7136000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                         000000007565dc05 6 bytes JMP 7133000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendInput                                                                                   000000007565ff3a 3 bytes JMP 7130000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendInput + 4                                                                               000000007565ff3e 2 bytes JMP 7130000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                            0000000075679fa4 6 bytes JMP 7115000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                               0000000075681533 6 bytes JMP 7106000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!mouse_event                                                                                 000000007569030f 6 bytes JMP 716c000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                 0000000075690353 6 bytes JMP 716f000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                        0000000075696d94 6 bytes JMP 7142000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                          0000000075696df5 6 bytes JMP 713c000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!BlockInput                                                                                  0000000075697e6f 3 bytes JMP 7118000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!BlockInput + 4                                                                              0000000075697e73 2 bytes JMP 7118000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                     0000000075698983 3 bytes JMP 7124000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices + 4                                                                 0000000075698987 2 bytes JMP 7124000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                             0000000075c39cbb 6 bytes JMP 7199000a
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                    0000000076751401 2 bytes JMP 7622b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                      0000000076751419 2 bytes JMP 7622b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                    0000000076751431 2 bytes JMP 762a9149 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                    000000007675144a 2 bytes CALL 76204885 C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                                 * 9
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                       00000000767514dd 2 bytes JMP 762a8a42 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                00000000767514f5 2 bytes JMP 762a8c18 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                       000000007675150d 2 bytes JMP 762a8938 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                0000000076751525 2 bytes JMP 762a8d02 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                      000000007675153d 2 bytes JMP 7621fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                           0000000076751555 2 bytes JMP 76226907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                    000000007675156d 2 bytes JMP 762a9201 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                      0000000076751585 2 bytes JMP 762a8d62 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                         000000007675159d 2 bytes JMP 762a88fc C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                      00000000767515b5 2 bytes JMP 7621fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                    00000000767515cd 2 bytes JMP 7622b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                00000000767516b2 2 bytes JMP 762a90c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[840] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                00000000767516bd 2 bytes JMP 762a8891 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\RPCRT4.dll!RpcServerRegisterIfEx                                                                                                           000007fefddf2930 6 bytes {JMP QWORD [RIP+0x25d700]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes JMP 650061
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xb7e4c]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x9781c]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xd72c4]}
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes JMP 2000
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[872] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                                            0000000076e8beb0 8 bytes JMP 000000006fff00d8
.text   C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                         0000000076e8c060 8 bytes JMP 000000006fff0148
.text   C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                       0000000076e8c280 1 byte JMP 000000006fff0110
.text   C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 2                                                                                   0000000076e8c282 6 bytes {JMP 0xfffffffff9163e90}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                  0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                       0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                        0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                          0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                        0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                          0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                        000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                          000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                         000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                       000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                       000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                        000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                      000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                          000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\system32\svchost.exe[1016] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\System32\svchost.exe[344] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes JMP da97e5d2
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes JMP d4e7d965
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes JMP 9954140
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes JMP e4d7e4d7
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes JMP 9773e68
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes JMP 43004f
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes JMP 8c70a60
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes JMP afb80
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes JMP 7ef65e1
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes JMP 99280
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes JMP 56b7009
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes JMP 7c267f1
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes JMP 6de9239
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes JMP df45df45
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes JMP 450044
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes JMP 50002d
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes JMP 7083659
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes JMP 8c53551
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes JMP 7eaf2d8
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\System32\svchost.exe[500] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\system32\svchost.exe[352] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes JMP 209360
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                  0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                       0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                        0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                          0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                        0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                          0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\RPCRT4.dll!RpcServerRegisterIfEx                                                                                                          000007fefddf2930 6 bytes {JMP QWORD [RIP+0x25d700]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                        000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xfdd50]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                          000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x11dca0]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                         000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x138abc]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                       000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xb7e4c]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                       000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x9781c]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                        000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xd72c4]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                      000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x17458c]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                          000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x153890]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\SHELL32.dll!SHFileOperationW                                                                                                              000007fefe418f0c 5 bytes [FF, 25, 24, 71, DB]
.text   C:\Windows\system32\svchost.exe[1032] C:\Windows\system32\SHELL32.dll!SHFileOperation                                                                                                               000007fefe633214 6 bytes {JMP QWORD [RIP+0xb6ce1c]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                  0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                       0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                        0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                          0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                        0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                          0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                        000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0x2cdd50]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                          000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x2edca0]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                         000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x308abc]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                       000007fefdfe81e4 6 bytes JMP 0
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                       000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x26781c]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                        000007fefdfe8d6c 6 bytes JMP 0
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                      000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x34458c]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                          000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x323890]}
.text   C:\Windows\System32\spoolsv.exe[1336] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x379320]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                  0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                       0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                        0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                          0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                        0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                          0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\RPCRT4.dll!RpcServerRegisterIfEx                                                                                                          000007fefddf2930 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                        000007fefdfe22e0 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                          000007fefdfe2390 6 bytes JMP 5
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                         000007fefdfe7574 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                       000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xb7e4c]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                       000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x9781c]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                        000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xd72c4]}
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                      000007fefdfebaa4 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                          000007fefdfec7a0 6 bytes JMP 0
.text   C:\Windows\system32\svchost.exe[1396] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x209320]}
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                            000000007703f9f0 3 bytes JMP 71af000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4                                                                                        000000007703f9f4 2 bytes JMP 71af000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess                                                                            000000007703fb38 3 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess + 4                                                                        000000007703fb3c 2 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                                 000000007703fcc0 3 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4                                                                             000000007703fcc4 2 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                         000000007703fd74 3 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4                                                                                     000000007703fd78 2 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                                      000000007703fdd8 3 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4                                                                                  000000007703fddc 2 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                            000000007703fed0 3 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4                                                                        000000007703fed4 2 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent                                                                                      000000007703ff84 3 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent + 4                                                                                  000000007703ff88 2 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                                    000000007703ffb4 3 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4                                                                                000000007703ffb8 2 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                                     0000000077040014 3 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4                                                                                 0000000077040018 2 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                                  0000000077040094 3 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4                                                                              0000000077040098 2 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                       00000000770400c4 3 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4                                                                                   00000000770400c8 2 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                                  00000000770403c8 3 bytes JMP 70b5000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4                                                                              00000000770403cc 2 bytes JMP 70b5000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort                                                                                   00000000770403e0 3 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort + 4                                                                               00000000770403e4 2 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                          0000000077040560 3 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4                                                                      0000000077040564 2 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                                      00000000770406a4 3 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4                                                                                  00000000770406a8 2 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair                                                                                  0000000077040704 3 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair + 4                                                                              0000000077040708 2 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                                     00000000770407ac 3 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant + 4                                                                                 00000000770407b0 2 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort                                                                                       00000000770407f4 3 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort + 4                                                                                   00000000770407f8 2 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore                                                                                  0000000077040884 3 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore + 4                                                                              0000000077040888 2 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                         000000007704089c 3 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4                                                                     00000000770408a0 2 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                                   00000000770408b4 3 bytes JMP 70b8000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4                                                                               00000000770408b8 2 bytes JMP 70b8000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                                       0000000077040e04 3 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4                                                                                   0000000077040e08 2 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                              0000000077040ee8 3 bytes JMP 70be000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4                                                                          0000000077040eec 2 bytes JMP 70be000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                             0000000077041bf4 3 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4                                                                         0000000077041bf8 2 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                                   0000000077041cc4 3 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4                                                                               0000000077041cc8 2 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                               0000000077041d9c 3 bytes JMP 70df000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4                                                                           0000000077041da0 2 bytes JMP 70df000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                                       000000007705d2f6 6 bytes JMP 71a8000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW                                                                          0000000076213bbb 3 bytes JMP 719c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW + 4                                                                      0000000076213bbf 2 bytes JMP 719c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressW                                                                           0000000076219abc 6 bytes JMP 7187000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!CopyFileExW                                                                                     0000000076223b7a 6 bytes JMP 717e000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressA                                                                           000000007622cd11 6 bytes JMP 718a000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedA                                                                             000000007627ddde 6 bytes JMP 7184000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW                                                                             000000007627de81 3 bytes JMP 7181000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW + 4                                                                         000000007627de85 2 bytes JMP 7181000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                                  00000000769af8a7 6 bytes JMP 719f000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 559                                                                          00000000769b2e0b 4 bytes CALL 71ac0000
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetWindowLongW                                                                                    0000000075638332 6 bytes JMP 7157000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                                0000000075638bff 6 bytes JMP 714b000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                             00000000756390d3 6 bytes JMP 7106000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                                      0000000075639679 6 bytes JMP 7145000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                               00000000756397d2 6 bytes JMP 713f000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                                   000000007563ee21 6 bytes JMP 715d000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                                    000000007563efe1 3 bytes JMP 710c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!RegisterHotKey + 4                                                                                000000007563efe5 2 bytes JMP 710c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                                      00000000756412bd 6 bytes JMP 7151000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                       0000000075642797 6 bytes JMP 7124000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                                        0000000075643ef0 3 bytes JMP 7118000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!MoveWindow + 4                                                                                    0000000075643ef4 2 bytes JMP 7118000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetParent                                                                                         00000000756445cc 3 bytes JMP 711b000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetParent + 4                                                                                     00000000756445d0 2 bytes JMP 711b000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                      000000007564460c 6 bytes JMP 7103000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                  0000000075644713 6 bytes JMP 7121000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                                  00000000756447e5 3 bytes JMP 7127000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!GetKeyboardState + 4                                                                              00000000756447e9 2 bytes JMP 7127000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                                      0000000075644bbc 6 bytes JMP 7154000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                                0000000075644d1d 6 bytes JMP 714e000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetWindowLongA                                                                                    00000000756471e0 6 bytes JMP 715a000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                                      00000000756471fe 6 bytes JMP 7148000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                             0000000075647d59 6 bytes JMP 7109000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                                 00000000756481f5 6 bytes JMP 7160000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                                000000007564825a 6 bytes JMP 7133000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                              00000000756482d2 6 bytes JMP 7139000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                               0000000075648411 6 bytes JMP 7142000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                                 0000000075648f4c 6 bytes JMP 7163000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                                000000007564cc1e 3 bytes JMP 7115000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SetClipboardViewer + 4                                                                            000000007564cc22 2 bytes JMP 7115000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                               000000007565a072 6 bytes JMP 7130000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                               000000007565dc05 6 bytes JMP 712d000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendInput                                                                                         000000007565ff3a 3 bytes JMP 712a000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendInput + 4                                                                                     000000007565ff3e 2 bytes JMP 712a000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                                  0000000075679fa4 6 bytes JMP 710f000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                                     0000000075681533 6 bytes JMP 7100000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!mouse_event                                                                                       000000007569030f 6 bytes JMP 7166000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                       0000000075690353 6 bytes JMP 7169000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                              0000000075696d94 6 bytes JMP 713c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                                0000000075696df5 6 bytes JMP 7136000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!BlockInput                                                                                        0000000075697e6f 3 bytes JMP 7112000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!BlockInput + 4                                                                                    0000000075697e73 2 bytes JMP 7112000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                           0000000075698983 3 bytes JMP 711e000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices + 4                                                                       0000000075698987 2 bytes JMP 711e000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                           0000000075d658b3 6 bytes JMP 718d000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                             0000000075d65ea5 6 bytes JMP 7175000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                          0000000075d67bcc 6 bytes JMP 7196000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                           0000000075d6b98a 6 bytes JMP 7190000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                         0000000075d6bd7d 6 bytes JMP 716c000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                            0000000075d6cf11 6 bytes JMP 7172000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                          0000000075d6e935 6 bytes JMP 7193000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                             0000000075d94aaa 6 bytes JMP 716f000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\SHELL32.dll!SHFileOperationW                                                                                 0000000074a29670 6 bytes JMP 7178000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\SHELL32.dll!SHFileOperation                                                                                  0000000074c2c509 6 bytes JMP 717b000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                                   0000000075c39cbb 6 bytes JMP 7199000a
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                          0000000076751401 2 bytes JMP 7622b233 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                            0000000076751419 2 bytes JMP 7622b35e C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                          0000000076751431 2 bytes JMP 762a9149 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                          000000007675144a 2 bytes CALL 76204885 C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                                 * 9
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                             00000000767514dd 2 bytes JMP 762a8a42 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                      00000000767514f5 2 bytes JMP 762a8c18 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                             000000007675150d 2 bytes JMP 762a8938 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                      0000000076751525 2 bytes JMP 762a8d02 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                            000000007675153d 2 bytes JMP 7621fcc0 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                 0000000076751555 2 bytes JMP 76226907 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                          000000007675156d 2 bytes JMP 762a9201 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                            0000000076751585 2 bytes JMP 762a8d62 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                               000000007675159d 2 bytes JMP 762a88fc C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                            00000000767515b5 2 bytes JMP 7621fd59 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                          00000000767515cd 2 bytes JMP 7622b2f4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                      00000000767516b2 2 bytes JMP 762a90c4 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                      00000000767516bd 2 bytes JMP 762a8891 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                           0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                     0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                             0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                          0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                          0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                        0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                         0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                      0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                           0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                      0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                       0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                              0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                          0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                      0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                         0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                           0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                      0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                             0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                       0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                           0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                  0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                 0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                       0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                   0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                         0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                              0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                               0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                 0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                               0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                 0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                      000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                               000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                 000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                              000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                              000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!GetPixel                                                                                               000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                             000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                 000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                       000007fefd1b6d10 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                         000007fefdfe22e0 6 bytes JMP 1d1620
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x2edca0]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x308abc]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                        000007fefdfe81e4 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                        000007fefdfe8814 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                         000007fefdfe8d6c 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                       000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x34458c]}
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                           000007fefdfec7a0 6 bytes JMP 0
.text   C:\Windows\system32\nvvsvc.exe[1636] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                 000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x379320]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                     0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                          0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                          0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                               0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                       0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                    0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                          0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                    0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                  0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                   0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                     0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                 0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                        0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                    0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                   0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                     0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                       0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                 0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                     0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                            0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                           0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                 0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                             0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                   0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                        0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                         0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                           0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                         0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                           0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                         000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!BitBlt                                                                                           000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                          000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                        000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                        000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!GetPixel                                                                                         000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                       000007fefdfebaa4 6 bytes JMP d14
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                           000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe[1712] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                 000007fefd1b6d10 6 bytes JMP 650070
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                      000000007703f9f0 3 bytes JMP 71af000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4                                                                  000000007703f9f4 2 bytes JMP 71af000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess                                                      000000007703fb38 3 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess + 4                                                  000000007703fb3c 2 bytes JMP 70c1000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                           000000007703fcc0 3 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4                                                       000000007703fcc4 2 bytes JMP 70e2000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                   000000007703fd74 3 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4                                                               000000007703fd78 2 bytes JMP 70cd000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                000000007703fdd8 3 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4                                                            000000007703fddc 2 bytes JMP 70d3000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                      000000007703fed0 3 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4                                                  000000007703fed4 2 bytes JMP 70ca000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent                                                                000000007703ff84 3 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent + 4                                                            000000007703ff88 2 bytes JMP 70fa000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                              000000007703ffb4 3 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4                                                          000000007703ffb8 2 bytes JMP 70d6000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                               0000000077040014 3 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4                                                           0000000077040018 2 bytes JMP 70ee000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                            0000000077040094 3 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4                                                        0000000077040098 2 bytes JMP 70eb000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                 00000000770400c4 3 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4                                                             00000000770400c8 2 bytes JMP 70d0000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                            00000000770403c8 3 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4                                                        00000000770403cc 2 bytes JMP 70bb000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort                                                             00000000770403e0 3 bytes JMP 7100000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort + 4                                                         00000000770403e4 2 bytes JMP 7100000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                    0000000077040560 3 bytes JMP 7103000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4                                                0000000077040564 2 bytes JMP 7103000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                00000000770406a4 3 bytes JMP 70df000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4                                                            00000000770406a8 2 bytes JMP 70df000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair                                                            0000000077040704 3 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair + 4                                                        0000000077040708 2 bytes JMP 70f7000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                               00000000770407ac 3 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant + 4                                                           00000000770407b0 2 bytes JMP 70fd000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort                                                                 00000000770407f4 3 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort + 4                                                             00000000770407f8 2 bytes JMP 70f1000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore                                                            0000000077040884 3 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore + 4                                                        0000000077040888 2 bytes JMP 70f4000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                   000000007704089c 3 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4                                               00000000770408a0 2 bytes JMP 70c7000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                             00000000770408b4 3 bytes JMP 70be000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4                                                         00000000770408b8 2 bytes JMP 70be000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                 0000000077040e04 3 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4                                                             0000000077040e08 2 bytes JMP 70dc000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                        0000000077040ee8 3 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4                                                    0000000077040eec 2 bytes JMP 70c4000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                       0000000077041bf4 3 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4                                                   0000000077041bf8 2 bytes JMP 70d9000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                             0000000077041cc4 3 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4                                                         0000000077041cc8 2 bytes JMP 70e8000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                         0000000077041d9c 3 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4                                                     0000000077041da0 2 bytes JMP 70e5000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                 000000007705d2f6 6 bytes JMP 71a8000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!CreateProcessInternalW                                                    0000000076213bbb 3 bytes JMP 719c000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!CreateProcessInternalW + 4                                                0000000076213bbf 2 bytes JMP 719c000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!MoveFileWithProgressW                                                     0000000076219abc 6 bytes JMP 7187000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!CopyFileExW                                                               0000000076223b7a 6 bytes JMP 717e000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!MoveFileWithProgressA                                                     000000007622cd11 6 bytes JMP 718a000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!MoveFileTransactedA                                                       000000007627ddde 6 bytes JMP 7184000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!MoveFileTransactedW                                                       000000007627de81 3 bytes JMP 7181000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNEL32.dll!MoveFileTransactedW + 4                                                   000000007627de85 2 bytes JMP 7181000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                            00000000769af8a7 6 bytes JMP 719f000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 559                                                    00000000769b2e0b 4 bytes CALL 71ac0000
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetWindowLongW                                                              0000000075638332 6 bytes JMP 715d000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                          0000000075638bff 6 bytes JMP 7151000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                       00000000756390d3 6 bytes JMP 710c000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                0000000075639679 6 bytes JMP 714b000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                         00000000756397d2 6 bytes JMP 7145000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                             000000007563ee21 6 bytes JMP 7163000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                              000000007563efe1 3 bytes JMP 7112000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!RegisterHotKey + 4                                                          000000007563efe5 2 bytes JMP 7112000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                00000000756412bd 6 bytes JMP 7157000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                 0000000075642797 6 bytes JMP 712a000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                  0000000075643ef0 3 bytes JMP 711e000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!MoveWindow + 4                                                              0000000075643ef4 2 bytes JMP 711e000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetParent                                                                   00000000756445cc 3 bytes JMP 7121000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetParent + 4                                                               00000000756445d0 2 bytes JMP 7121000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                000000007564460c 6 bytes JMP 7109000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                            0000000075644713 6 bytes JMP 7127000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                            00000000756447e5 3 bytes JMP 712d000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!GetKeyboardState + 4                                                        00000000756447e9 2 bytes JMP 712d000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                0000000075644bbc 6 bytes JMP 715a000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                          0000000075644d1d 6 bytes JMP 7154000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetWindowLongA                                                              00000000756471e0 6 bytes JMP 7160000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                00000000756471fe 6 bytes JMP 714e000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                       0000000075647d59 6 bytes JMP 710f000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                           00000000756481f5 6 bytes JMP 7166000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                          000000007564825a 6 bytes JMP 7139000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                        00000000756482d2 6 bytes JMP 713f000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                         0000000075648411 6 bytes JMP 7148000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                           0000000075648f4c 6 bytes JMP 7169000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                          000000007564cc1e 3 bytes JMP 711b000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SetClipboardViewer + 4                                                      000000007564cc22 2 bytes JMP 711b000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                         000000007565a072 6 bytes JMP 7136000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                         000000007565dc05 6 bytes JMP 7133000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendInput                                                                   000000007565ff3a 3 bytes JMP 7130000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendInput + 4                                                               000000007565ff3e 2 bytes JMP 7130000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                            0000000075679fa4 6 bytes JMP 7115000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                               0000000075681533 6 bytes JMP 7106000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!mouse_event                                                                 000000007569030f 6 bytes JMP 716c000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!keybd_event                                                                 0000000075690353 6 bytes JMP 716f000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                        0000000075696d94 6 bytes JMP 7142000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                          0000000075696df5 6 bytes JMP 713c000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!BlockInput                                                                  0000000075697e6f 3 bytes JMP 7118000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!BlockInput + 4                                                              0000000075697e73 2 bytes JMP 7118000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                     0000000075698983 3 bytes JMP 7124000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices + 4                                                 0000000075698987 2 bytes JMP 7124000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                     0000000075d658b3 6 bytes JMP 718d000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                       0000000075d65ea5 6 bytes JMP 717b000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                    0000000075d67bcc 6 bytes JMP 7196000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                     0000000075d6b98a 6 bytes JMP 7190000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                   0000000075d6bd7d 6 bytes JMP 7172000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                      0000000075d6cf11 6 bytes JMP 7178000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                    0000000075d6e935 6 bytes JMP 7193000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                       0000000075d94aaa 6 bytes JMP 7175000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                    0000000076751401 2 bytes JMP 7622b233 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                      0000000076751419 2 bytes JMP 7622b35e C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                    0000000076751431 2 bytes JMP 762a9149 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                    000000007675144a 2 bytes CALL 76204885 C:\Windows\syswow64\KERNEL32.dll
.text   ...                                                                                                                                                                                                 * 9
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                       00000000767514dd 2 bytes JMP 762a8a42 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                00000000767514f5 2 bytes JMP 762a8c18 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                       000000007675150d 2 bytes JMP 762a8938 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                0000000076751525 2 bytes JMP 762a8d02 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                      000000007675153d 2 bytes JMP 7621fcc0 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                           0000000076751555 2 bytes JMP 76226907 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                    000000007675156d 2 bytes JMP 762a9201 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                      0000000076751585 2 bytes JMP 762a8d62 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                         000000007675159d 2 bytes JMP 762a88fc C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                      00000000767515b5 2 bytes JMP 7621fd59 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                    00000000767515cd 2 bytes JMP 7622b2f4 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                00000000767516b2 2 bytes JMP 762a90c4 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                00000000767516bd 2 bytes JMP 762a8891 C:\Windows\syswow64\KERNEL32.dll
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\shell32.dll!SHFileOperationW                                                           0000000074a29670 6 bytes JMP 70b5000a
.text   C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[1744] C:\Windows\syswow64\shell32.dll!SHFileOperation                                                            0000000074c2c509 6 bytes JMP 70b8000a
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\System32\svchost.exe[1920] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                   0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                        0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                        0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                             0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                     0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                  0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                        0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                  0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                 0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                              0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                   0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                              0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                               0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                      0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                  0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                              0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                 0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                   0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                              0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                     0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                               0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                   0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                          0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                         0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                               0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                           0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                 0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                      0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                       0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                         0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                       0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\taskhost.exe[2032] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                         0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                      0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                           0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                            0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                              0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                            0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                              0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                   000007fefcd63a50 5 bytes JMP a21
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                            000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                              000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                             000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x128abc]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                           000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                           000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                            000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                          000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                              000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Windows\system32\Dwm.exe[1656] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                    000007fefd1b6d10 6 bytes JMP 0
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                            0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                                 0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                                 0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                                      0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                              0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                           0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                                 0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                           0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                         0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                          0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                                       0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                            0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                                       0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                        0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                               0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                           0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                                       0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                          0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                            0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                                       0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                              0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                        0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                            0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                                   0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                                  0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                        0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                                    0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                                                          0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                                               0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                                                0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                                                  0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                                                0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                                                  0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                       000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                                                000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0x2cdd50]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                                                  000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x2edca0]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                                                 000007fefdfe7574 6 bytes {JMP QWORD [RIP+0x308abc]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                                               000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0x287e4c]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                                               000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x26781c]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                                                000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0x2a72c4]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                                              000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x34458c]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                                                  000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x323890]}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                                        000007fefd1b6d10 6 bytes JMP 2c303238
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\WS2_32.dll!WSASend                                                                                                                                000007fefdd013b0 7 bytes {MOV EAX, 0x3aae9a0; JMP RAX}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\WS2_32.dll!closesocket                                                                                                                            000007fefdd018e0 7 bytes {MOV EAX, 0x3aae030; JMP RAX}
.text   C:\Windows\Explorer.EXE[2080] C:\Windows\system32\WS2_32.dll!send                                                                                                                                   000007fefdd07cd0 7 bytes {MOV EAX, 0x3aae950; JMP RAX}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                       000007fefdfe22e0 6 bytes {JMP QWORD [RIP+0xedd50]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                         000007fefdfe2390 6 bytes {JMP QWORD [RIP+0x10dca0]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                        000007fefdfe7574 6 bytes JMP 0
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                      000007fefdfe81e4 6 bytes {JMP QWORD [RIP+0xa7e4c]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                      000007fefdfe8814 6 bytes {JMP QWORD [RIP+0x8781c]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                       000007fefdfe8d6c 6 bytes {JMP QWORD [RIP+0xc72c4]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                     000007fefdfebaa4 6 bytes {JMP QWORD [RIP+0x16458c]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                         000007fefdfec7a0 6 bytes {JMP QWORD [RIP+0x143890]}
.text   C:\Program Files\Logitech\SetPointP\SetPoint.exe[2108] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                               000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x4e9320]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                 0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                      0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                      0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                           0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                   0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                      0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                              0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                               0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                            0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                 0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                            0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                             0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                    0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                            0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                               0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                 0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                            0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                   0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                             0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                 0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                        0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                       0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                             0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                         0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!CopyFileExW                                                                                               0000000076d31870 6 bytes {JMP QWORD [RIP+0x93ce7c0]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!CreateProcessInternalW                                                                                    0000000076d3dd20 6 bytes {JMP QWORD [RIP+0x9322310]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW                                                                                     0000000076daf6e0 6 bytes {JMP QWORD [RIP+0x92f0950]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!MoveFileTransactedW                                                                                       0000000076daf710 6 bytes {JMP QWORD [RIP+0x9330920]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!MoveFileWithProgressA                                                                                     0000000076daf8e0 6 bytes {JMP QWORD [RIP+0x92d0750]}
.text   C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe[2520] C:\Windows\system32\kernel32.dll!MoveFileTransactedA                                                                                       0000000076db5730 6 bytes {JMP QWORD [RIP+0x930a900]}
.text   C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe[3336] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                                              0000000076e8beb0 8 bytes JMP 000000006fff0148
.text   C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe[3336] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                           0000000076e8c060 8 bytes JMP 000000006fff0110
.text   C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe[3336] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                         0000000076e8c280 8 bytes JMP 000000006fff00d8
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                              0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                   0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                   0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                        0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                             0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                   0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                             0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                           0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                            0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                         0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                              0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                         0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                          0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                 0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                             0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                         0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                            0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                              0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                         0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                          0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                              0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                     0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                    0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                          0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                      0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\SearchIndexer.exe[3884] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                                          000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x379320]}
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[2328] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                            000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[2328] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                             000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x379320]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                                    0000000076e62280 6 bytes {JMP QWORD [RIP+0x91dddb0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                                         0000000076e8be20 6 bytes {JMP QWORD [RIP+0x9194210]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess                                                                                                         0000000076e8bef0 6 bytes {JMP QWORD [RIP+0x99d4140]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                                              0000000076e8bff0 6 bytes {JMP QWORD [RIP+0x9874040]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                                      0000000076e8c060 6 bytes {JMP QWORD [RIP+0x9953fd0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                                   0000000076e8c0a0 6 bytes {JMP QWORD [RIP+0x9913f90]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                                         0000000076e8c140 6 bytes {JMP QWORD [RIP+0x9973ef0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                                                                                                                   0000000076e8c1b0 6 bytes {JMP QWORD [RIP+0x9773e80]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                                                 0000000076e8c1d0 6 bytes {JMP QWORD [RIP+0x98f3e60]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                                  0000000076e8c210 6 bytes {JMP QWORD [RIP+0x97f3e20]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                                               0000000076e8c260 6 bytes {JMP QWORD [RIP+0x9813dd0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                                    0000000076e8c280 6 bytes {JMP QWORD [RIP+0x9933db0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                                               0000000076e8c470 6 bytes {JMP QWORD [RIP+0x9a13bc0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcCreatePort                                                                                                                0000000076e8c480 6 bytes {JMP QWORD [RIP+0x9733bb0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                       0000000076e8c580 6 bytes {JMP QWORD [RIP+0x9713ab0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                                   0000000076e8c650 6 bytes {JMP QWORD [RIP+0x98939e0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                                                                                                               0000000076e8c690 6 bytes {JMP QWORD [RIP+0x97939a0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                                                                                                                  0000000076e8c700 6 bytes {JMP QWORD [RIP+0x9753930]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreatePort                                                                                                                    0000000076e8c730 6 bytes {JMP QWORD [RIP+0x97d3900]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                                                                                                               0000000076e8c790 6 bytes {JMP QWORD [RIP+0x97b38a0]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                      0000000076e8c7a0 6 bytes {JMP QWORD [RIP+0x9993890]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                                                0000000076e8c7b0 6 bytes {JMP QWORD [RIP+0x99f3880]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                                    0000000076e8cb20 6 bytes {JMP QWORD [RIP+0x98b3510]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                                           0000000076e8cbb0 6 bytes {JMP QWORD [RIP+0x99b3480]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                                          0000000076e8d420 6 bytes {JMP QWORD [RIP+0x98d2c10]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                                                0000000076e8d4a0 6 bytes {JMP QWORD [RIP+0x9832b90]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                                            0000000076e8d520 6 bytes {JMP QWORD [RIP+0x9852b10]}
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\System32\KERNELBASE.dll!SetProcessShutdownParameters                                                                                               000007fefcd63a50 5 bytes [FF, 25, E0, C5, 0A]
.text   C:\Windows\system32\AUDIODG.EXE[4956] C:\Windows\System32\ole32.dll!CoCreateInstance                                                                                                                000007fefd1b6d10 6 bytes {JMP QWORD [RIP+0x379320]}
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                                                                 000000007703f9f0 3 bytes JMP 71af000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtClose + 4                                                                                                                             000000007703f9f4 2 bytes JMP 71af000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess                                                                                                                 000000007703fb38 3 bytes JMP 70c1000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationProcess + 4                                                                                                             000000007703fb3c 2 bytes JMP 70c1000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                                                                      000000007703fcc0 3 bytes JMP 70e2000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess + 4                                                                                                                  000000007703fcc4 2 bytes JMP 70e2000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                                                              000000007703fd74 3 bytes JMP 70cd000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4                                                                                                                          000000007703fd78 2 bytes JMP 70cd000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                                                                           000000007703fdd8 3 bytes JMP 70d3000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection + 4                                                                                                                       000000007703fddc 2 bytes JMP 70d3000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                                                                 000000007703fed0 3 bytes JMP 70ca000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken + 4                                                                                                             000000007703fed4 2 bytes JMP 70ca000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent                                                                                                                           000000007703ff84 3 bytes JMP 70fa000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateEvent + 4                                                                                                                       000000007703ff88 2 bytes JMP 70fa000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                                                                         000000007703ffb4 3 bytes JMP 70d6000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4                                                                                                                     000000007703ffb8 2 bytes JMP 70d6000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                                                                          0000000077040014 3 bytes JMP 70ee000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread + 4                                                                                                                      0000000077040018 2 bytes JMP 70ee000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                                                                       0000000077040094 3 bytes JMP 70eb000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread + 4                                                                                                                   0000000077040098 2 bytes JMP 70eb000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                                                            00000000770400c4 3 bytes JMP 70d0000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4                                                                                                                        00000000770400c8 2 bytes JMP 70d0000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                                                                       00000000770403c8 3 bytes JMP 70bb000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort + 4                                                                                                                   00000000770403cc 2 bytes JMP 70bb000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort                                                                                                                        00000000770403e0 3 bytes JMP 7100000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcCreatePort + 4                                                                                                                    00000000770403e4 2 bytes JMP 7100000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                                               0000000077040560 3 bytes JMP 7103000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort + 4                                                                                                           0000000077040564 2 bytes JMP 7103000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                                                                           00000000770406a4 3 bytes JMP 70df000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort + 4                                                                                                                       00000000770406a8 2 bytes JMP 70df000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair                                                                                                                       0000000077040704 3 bytes JMP 70f7000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateEventPair + 4                                                                                                                   0000000077040708 2 bytes JMP 70f7000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant                                                                                                                          00000000770407ac 3 bytes JMP 70fd000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateMutant + 4                                                                                                                      00000000770407b0 2 bytes JMP 70fd000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort                                                                                                                            00000000770407f4 3 bytes JMP 70f1000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreatePort + 4                                                                                                                        00000000770407f8 2 bytes JMP 70f1000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore                                                                                                                       0000000077040884 3 bytes JMP 70f4000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSemaphore + 4                                                                                                                   0000000077040888 2 bytes JMP 70f4000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                                                              000000007704089c 3 bytes JMP 70c7000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4                                                                                                          00000000770408a0 2 bytes JMP 70c7000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                                                                        00000000770408b4 3 bytes JMP 70be000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 4                                                                                                                    00000000770408b8 2 bytes JMP 70be000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                                                                            0000000077040e04 3 bytes JMP 70dc000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver + 4                                                                                                                        0000000077040e08 2 bytes JMP 70dc000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                                                                   0000000077040ee8 3 bytes JMP 70c4000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject + 4                                                                                                               0000000077040eec 2 bytes JMP 70c4000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                                                                  0000000077041bf4 3 bytes JMP 70d9000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation + 4                                                                                                              0000000077041bf8 2 bytes JMP 70d9000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                                                                        0000000077041cc4 3 bytes JMP 70e8000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem + 4                                                                                                                    0000000077041cc8 2 bytes JMP 70e8000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                                                                    0000000077041d9c 3 bytes JMP 70e5000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl + 4                                                                                                                0000000077041da0 2 bytes JMP 70e5000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                                                                            000000007705d2f6 6 bytes JMP 71a8000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW                                                                                                               0000000076213bbb 3 bytes JMP 719c000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW + 4                                                                                                           0000000076213bbf 2 bytes JMP 719c000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressW                                                                                                                0000000076219abc 6 bytes JMP 7187000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!CopyFileExW                                                                                                                          0000000076223b7a 6 bytes JMP 717e000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!MoveFileWithProgressA                                                                                                                000000007622cd11 6 bytes JMP 718a000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedA                                                                                                                  000000007627ddde 6 bytes JMP 7184000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW                                                                                                                  000000007627de81 3 bytes JMP 7181000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\kernel32.dll!MoveFileTransactedW + 4                                                                                                              000000007627de85 2 bytes JMP 7181000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                                                                       00000000769af8a7 6 bytes JMP 719f000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 559                                                                                                               00000000769b2e0b 4 bytes CALL 71ac0000
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetWindowLongW                                                                                                                         0000000075638332 6 bytes JMP 715d000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                                                                     0000000075638bff 6 bytes JMP 7151000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                                                                  00000000756390d3 6 bytes JMP 710c000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                                                                           0000000075639679 6 bytes JMP 714b000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                                                                    00000000756397d2 6 bytes JMP 7145000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                                                                        000000007563ee21 6 bytes JMP 7163000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                                                                         000000007563efe1 3 bytes JMP 7112000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!RegisterHotKey + 4                                                                                                                     000000007563efe5 2 bytes JMP 7112000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                                                                           00000000756412bd 6 bytes JMP 7157000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                                                            0000000075642797 6 bytes JMP 712a000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                                                                             0000000075643ef0 3 bytes JMP 711e000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!MoveWindow + 4                                                                                                                         0000000075643ef4 2 bytes JMP 711e000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetParent                                                                                                                              00000000756445cc 3 bytes JMP 7121000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetParent + 4                                                                                                                          00000000756445d0 2 bytes JMP 7121000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                                                           000000007564460c 6 bytes JMP 7109000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                                                       0000000075644713 6 bytes JMP 7127000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                                                                       00000000756447e5 3 bytes JMP 712d000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!GetKeyboardState + 4                                                                                                                   00000000756447e9 2 bytes JMP 712d000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                                                                           0000000075644bbc 6 bytes JMP 715a000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                                                                     0000000075644d1d 6 bytes JMP 7154000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetWindowLongA                                                                                                                         00000000756471e0 6 bytes JMP 7160000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                                                                           00000000756471fe 6 bytes JMP 714e000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                                                                  0000000075647d59 6 bytes JMP 710f000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                                                                      00000000756481f5 6 bytes JMP 7166000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                                                                     000000007564825a 6 bytes JMP 7139000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                                                                   00000000756482d2 6 bytes JMP 713f000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                                                                    0000000075648411 6 bytes JMP 7148000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                                                                      0000000075648f4c 6 bytes JMP 7169000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                                                                     000000007564cc1e 3 bytes JMP 711b000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SetClipboardViewer + 4                                                                                                                 000000007564cc22 2 bytes JMP 711b000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                                                                    000000007565a072 6 bytes JMP 7136000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                                                                    000000007565dc05 6 bytes JMP 7133000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendInput                                                                                                                              000000007565ff3a 3 bytes JMP 7130000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendInput + 4                                                                                                                          000000007565ff3e 2 bytes JMP 7130000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                                                                       0000000075679fa4 6 bytes JMP 7115000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                                                                          0000000075681533 6 bytes JMP 7106000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!mouse_event                                                                                                                            000000007569030f 6 bytes JMP 716c000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                                                            0000000075690353 6 bytes JMP 716f000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                                                                   0000000075696d94 6 bytes JMP 7142000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                                                                     0000000075696df5 6 bytes JMP 713c000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!BlockInput                                                                                                                             0000000075697e6f 3 bytes JMP 7118000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!BlockInput + 4                                                                                                                         0000000075697e73 2 bytes JMP 7118000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                                                                0000000075698983 3 bytes JMP 7124000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices + 4                                                                                                            0000000075698987 2 bytes JMP 7124000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                                                                0000000075d658b3 6 bytes JMP 718d000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                                                                  0000000075d65ea5 6 bytes JMP 717b000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                                                               0000000075d67bcc 6 bytes JMP 7196000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                                                                0000000075d6b98a 6 bytes JMP 7190000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                                                              0000000075d6bd7d 6 bytes JMP 7172000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                                                                 0000000075d6cf11 6 bytes JMP 7178000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                                                               0000000075d6e935 6 bytes JMP 7193000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                                                                  0000000075d94aaa 6 bytes JMP 7175000a
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                                               0000000076751401 2 bytes JMP 7622b233 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                                 0000000076751419 2 bytes JMP 7622b35e C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                                               0000000076751431 2 bytes JMP 762a9149 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                                               000000007675144a 2 bytes CALL 76204885 C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                                 * 9
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                                  00000000767514dd 2 bytes JMP 762a8a42 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                                           00000000767514f5 2 bytes JMP 762a8c18 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                                  000000007675150d 2 bytes JMP 762a8938 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                                           0000000076751525 2 bytes JMP 762a8d02 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                                 000000007675153d 2 bytes JMP 7621fcc0 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                                      0000000076751555 2 bytes JMP 76226907 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                                               000000007675156d 2 bytes JMP 762a9201 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                                 0000000076751585 2 bytes JMP 762a8d62 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                                    000000007675159d 2 bytes JMP 762a88fc C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                                 00000000767515b5 2 bytes JMP 7621fd59 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                                               00000000767515cd 2 bytes JMP 7622b2f4 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                                           00000000767516b2 2 bytes JMP 762a90c4 C:\Windows\syswow64\kernel32.dll
.text   F:\Pobrane\mwee7ntc.exe[5400] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                                           00000000767516bd 2 bytes JMP 762a8891 C:\Windows\syswow64\kernel32.dll

---- Threads - GMER 2.2 ----

Thread  C:\Windows\system32\taskhost.exe [2032:5380]                                                                                                                                                        000000000293ede0
Thread  C:\Windows\system32\taskhost.exe [2032:5412]                                                                                                                                                        000000000293e410
Thread  C:\Windows\system32\taskhost.exe [2032:5444]                                                                                                                                                        000000000293e620
Thread  C:\Windows\system32\taskhost.exe [2032:5476]                                                                                                                                                        000000000293ecb0
Thread  C:\Windows\system32\taskhost.exe [2032:5508]                                                                                                                                                        0000000002939280
Thread  C:\Windows\system32\taskhost.exe [2032:5540]                                                                                                                                                        0000000002937c10
Thread  C:\Windows\system32\taskhost.exe [2032:5572]                                                                                                                                                        00000000029372a0
Thread  C:\Windows\system32\taskhost.exe [2032:5600]                                                                                                                                                        0000000002937630
Thread  C:\Windows\Explorer.EXE [2080:4736]                                                                                                                                                                 0000000003aaa490
Thread  C:\Windows\Explorer.EXE [2080:668]                                                                                                                                                                  0000000003aa85a0
Thread  C:\Windows\Explorer.EXE [2080:1548]                                                                                                                                                                 0000000003aa7b90
Thread  C:\Windows\Explorer.EXE [2080:5012]                                                                                                                                                                 0000000003aa7ec0
Thread  C:\Windows\Explorer.EXE [2080:5616]                                                                                                                                                                 000000000394ede0
Thread  C:\Windows\Explorer.EXE [2080:5620]                                                                                                                                                                 000000000394e410
Thread  C:\Windows\Explorer.EXE [2080:5628]                                                                                                                                                                 000000000394e620
Thread  C:\Windows\Explorer.EXE [2080:5644]                                                                                                                                                                 000000000394ecb0
Thread  C:\Windows\Explorer.EXE [2080:5652]                                                                                                                                                                 0000000003949280
Thread  C:\Windows\Explorer.EXE [2080:5656]                                                                                                                                                                 0000000003947c10
Thread  C:\Windows\Explorer.EXE [2080:5660]                                                                                                                                                                 00000000039472a0
Thread  C:\Windows\Explorer.EXE [2080:5664]                                                                                                                                                                 0000000003947630
Thread  C:\Windows\system32\taskeng.exe [2140:5376]                                                                                                                                                         000000000254ede0
Thread  C:\Windows\system32\taskeng.exe [2140:5408]                                                                                                                                                         000000000254e410
Thread  C:\Windows\system32\taskeng.exe [2140:5440]                                                                                                                                                         000000000254e620
Thread  C:\Windows\system32\taskeng.exe [2140:5472]                                                                                                                                                         000000000254ecb0
Thread  C:\Windows\system32\taskeng.exe [2140:5504]                                                                                                                                                         0000000002549280
Thread  C:\Windows\system32\taskeng.exe [2140:5536]                                                                                                                                                         0000000002547c10
Thread  C:\Windows\system32\taskeng.exe [2140:5568]                                                                                                                                                         00000000025472a0
Thread  C:\Windows\system32\taskeng.exe [2140:5596]                                                                                                                                                         0000000002547630
Thread  C:\Windows\System32\taskmgr.exe [2356:5612]                                                                                                                                                         0000000002b3ede0
Thread  C:\Windows\System32\taskmgr.exe [2356:5624]                                                                                                                                                         0000000002b3e410
Thread  C:\Windows\System32\taskmgr.exe [2356:5632]                                                                                                                                                         0000000002b3e620
Thread  C:\Windows\System32\taskmgr.exe [2356:5636]                                                                                                                                                         0000000002b3ecb0
Thread  C:\Windows\System32\taskmgr.exe [2356:5640]                                                                                                                                                         0000000002b39280
Thread  C:\Windows\System32\taskmgr.exe [2356:5696]                                                                                                                                                         0000000002b37c10
Thread  C:\Windows\System32\taskmgr.exe [2356:5700]                                                                                                                                                         0000000002b372a0
Thread  C:\Windows\System32\taskmgr.exe [2356:5704]                                                                                                                                                         0000000002b37630
Thread   [4924:2564]                                                                                                                                                                                        000000007706f523
Thread   [4924:5080]                                                                                                                                                                                        000000006ab778c3
Thread   [4924:132]                                                                                                                                                                                         000000007707046c
Thread  C:\Windows\system32\wuauclt.exe [4448:5772]                                                                                                                                                         000000000220ede0
Thread  C:\Windows\system32\wuauclt.exe [4448:5776]                                                                                                                                                         000000000220e410
Thread  C:\Windows\system32\wuauclt.exe [4448:5780]                                                                                                                                                         000000000220e620
Thread  C:\Windows\system32\wuauclt.exe [4448:5784]                                                                                                                                                         000000000220ecb0
Thread  C:\Windows\system32\wuauclt.exe [4448:5788]                                                                                                                                                         0000000002209280
Thread  C:\Windows\system32\wuauclt.exe [4448:5792]                                                                                                                                                         0000000002207c10
Thread  C:\Windows\system32\wuauclt.exe [4448:5796]                                                                                                                                                         00000000022072a0
Thread  C:\Windows\system32\wuauclt.exe [4448:5800]                                                                                                                                                         0000000002207630
Thread  C:\Windows\system32\svchost.exe [4876:1404]                                                                                                                                                         0000000000080730
Thread  C:\Windows\system32\svchost.exe [4876:5016]                                                                                                                                                         000000000007b510
Thread  C:\Windows\system32\svchost.exe [4876:2752]                                                                                                                                                         000000000007a150
Thread  C:\Windows\system32\svchost.exe [4876:2888]                                                                                                                                                         00000000000805a0
Thread  C:\Windows\system32\svchost.exe [4876:3684]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:1436]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2176]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3772]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2264]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1200]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3740]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2180]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4348]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4960]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2112]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1660]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:896]                                                                                                                                                          0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4432]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:3472]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2732]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3396]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3436]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:2056]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3444]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4768]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1488]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:3116]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3440]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1724]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:856]                                                                                                                                                          0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:1788]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4720]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5092]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:704]                                                                                                                                                          0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4088]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:708]                                                                                                                                                          0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4688]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4116]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4428]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3632]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:984]                                                                                                                                                          0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2724]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:3168]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2096]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2120]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2072]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:1164]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1856]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1932]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5048]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4492]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1068]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1108]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1096]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:1092]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3964]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:1588]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4224]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:2572]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3140]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:340]                                                                                                                                                          0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5124]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5128]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5140]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5152]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5164]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5168]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5192]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5204]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5212]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5216]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5232]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5244]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5252]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5256]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5264]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5268]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5276]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5280]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5288]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5292]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5304]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5316]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5324]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5328]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5336]                                                                                                                                                         00000000049dede0
Thread  C:\Windows\system32\svchost.exe [4876:5340]                                                                                                                                                         00000000049decb0
Thread  C:\Windows\system32\svchost.exe [4876:5344]                                                                                                                                                         00000000049d9280
Thread  C:\Windows\system32\svchost.exe [4876:5348]                                                                                                                                                         00000000049d7c10
Thread  C:\Windows\system32\svchost.exe [4876:5352]                                                                                                                                                         00000000049d72a0
Thread  C:\Windows\system32\svchost.exe [4876:5356]                                                                                                                                                         00000000049d7630
Thread  C:\Windows\system32\svchost.exe [4876:5708]                                                                                                                                                         0000000004ac8d00
Thread  C:\Windows\system32\svchost.exe [4876:5712]                                                                                                                                                         0000000004ac7710
Thread  C:\Windows\system32\svchost.exe [4876:5716]                                                                                                                                                         0000000004ac6e00
Thread  C:\Windows\system32\svchost.exe [4876:5720]                                                                                                                                                         0000000004ac7130
Thread  C:\Windows\system32\svchost.exe [4876:5756]                                                                                                                                                         0000000004e5a490
Thread  C:\Windows\system32\svchost.exe [4876:5760]                                                                                                                                                         0000000004e585a0
Thread  C:\Windows\system32\svchost.exe [4876:5764]                                                                                                                                                         0000000004e57b90
Thread  C:\Windows\system32\svchost.exe [4876:5768]                                                                                                                                                         0000000004e57ec0
Thread  C:\Windows\system32\svchost.exe [4876:5968]                                                                                                                                                         0000000004a124a0
Thread  C:\Windows\system32\svchost.exe [4876:5972]                                                                                                                                                         0000000004a09580
Thread  C:\Windows\system32\svchost.exe [4876:5976]                                                                                                                                                         0000000004a07cb0
Thread  C:\Windows\system32\svchost.exe [4876:5980]                                                                                                                                                         0000000004a07240
Thread  C:\Windows\system32\svchost.exe [4876:5984]                                                                                                                                                         0000000004a075d0
Thread  C:\Windows\system32\svchost.exe [4876:5992]                                                                                                                                                         00000000098d7ca0
Thread  C:\Windows\system32\svchost.exe [4876:6040]                                                                                                                                                         00000000098d6550
Thread  C:\Windows\system32\svchost.exe [4876:6044]                                                                                                                                                         00000000098d6100
Thread  C:\Windows\system32\svchost.exe [4876:6048]                                                                                                                                                         00000000098d5fd0
Thread  C:\Windows\system32\svchost.exe [4876:4124]                                                                                                                                                         000000000007b340
Thread  C:\Windows\system32\svchost.exe [4876:5528]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:5560]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:5588]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4528]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3284]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3872]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3604]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:3508]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:3268]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:7016]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:4556]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:6348]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:2608]                                                                                                                                                         0000000000079310
Thread  C:\Windows\system32\svchost.exe [4876:4360]                                                                                                                                                         0000000000078f90
Thread  C:\Windows\system32\svchost.exe [4876:6384]                                                                                                                                                         0000000000079310

---- Registry - GMER 2.2 ----

Reg     HKLM\SYSTEM\CurrentControlSet\services\CmdAgent\Mode\Configurations@SymbolicLinkValue                                                                                                               0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\CmdAgent\Mode\Data@SymbolicLinkValue                                                                                                                         0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\CmdAgent\Mode\Options@SymbolicLinkValue                                                                                                                      0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\CmdAgent\Mode\Configurations@SymbolicLinkValue                                                                                                                   0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\CmdAgent\Mode\Data@SymbolicLinkValue                                                                                                                             0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\CmdAgent\Mode\Options@SymbolicLinkValue                                                                                                                          0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\Software\COMODO\Cam@SymbolicLinkValue                                                                                                                                                   0x5C 0x00 0x52 0x00 ...
Reg     HKLM\SYSTEM\Software\COMODO\Firewall Pro@SymbolicLinkValue                                                                                                                                          0x5C 0x00 0x52 0x00 ...
Reg     HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Pan Waski\AppData\Local\Logitech\xae Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe  1

---- EOF - GMER 2.2 ----
