Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Atomic Ads [Solved]

Malware Ad ware

  • This topic is locked This topic is locked

#16
bhzendner

bhzendner

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 219 posts

.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                               00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                                     00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                                     000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                                 000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[1972] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtClose                                  000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                       000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                               000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                            000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                  000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                          000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                           00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                        00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                             00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                        00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                            00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject               00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                         00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                             00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                    00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                   00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                         00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                     00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                               00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                             00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                         00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\kernel32.dll!CreateProcessW                        00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\kernel32.dll!CreateProcessA                        00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                  000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters        0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                  0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!DeleteDC                                 00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!BitBlt                                   0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!CreateDCA                                0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!StretchBlt                               000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!MaskBlt                                  000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!GetPixel                                 000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!CreateDCW                                000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\GDI32.dll!PlgBlt                                   0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                      0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                   0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageW                            0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                     0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetWinEventHook                         0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!RegisterHotKey                          0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!PostMessageW                            0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!GetKeyState                             0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetParent                               0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetParent + 2                           0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!EnableWindow                            0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!MoveWindow                              0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!PostMessageA                            0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                      0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageA                            0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                   0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                       0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                      0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                    0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                     0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                       0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                      0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                     0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                     0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                        0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!GetKeyboardState                        0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendInput                               0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!GetClipboardData                        0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                           0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!mouse_event                             0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!keybd_event                             0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                    0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                      0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!BlockInput                              0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1996] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                 0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                               00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                 00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                    00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                         00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                 00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                              00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                    00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                            00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                             00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                          00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                               00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                          00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                  00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                              00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                 00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                           00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                               00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                      00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                     00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                           00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                       00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                          000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                                    000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                                000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                   000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!BitBlt                                                                                     000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                    000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                  000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                  000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!GetPixel                                                                                   000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                 000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\Bonjour\mDNSResponder.exe[1104] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                     000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[1336] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                              000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                                   000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                           000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                                        000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                              000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                                      000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                                       00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                                    00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                                         00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                                    00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                            00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                                        00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                           00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                                     00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                                         00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                                00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                               00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                                     00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                                 00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                                           00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                                         00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                                                     00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                                                    00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                                                    00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                                              000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                                    0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                                              0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                             00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                               0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                            0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                           000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                              000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                             000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                            000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                               0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                                  0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                               0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                                        0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                                 0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                                     0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                                      0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                                        0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                                         0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetParent                                                                                           0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                                                       0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                                        0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                                          0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                                        0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                                  0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                                        0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                               0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                                   0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                                  0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                                0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                                 0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                                   0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                                  0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                                 0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                                 0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                                    0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                                    0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendInput                                                                                           0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                                    0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                                       0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!mouse_event                                                                                         0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!keybd_event                                                                                         0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                                0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                                  0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!BlockInput                                                                                          0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Windows\system32\crypserv.exe[1488] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                             0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[1088] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[2060] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                    00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                      00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                         00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                              00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                      00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                   00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                         00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                 00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                  00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                               00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                    00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                               00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                       00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                   00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                      00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                    00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                           00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                          00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                            00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                               000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!DeleteDC                                                                        000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!BitBlt                                                                          000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!MaskBlt                                                                         000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!CreateDCW                                                                       000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!CreateDCA                                                                       000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!GetPixel                                                                        000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!StretchBlt                                                                      000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe[2096] C:\Windows\system32\GDI32.dll!PlgBlt                                                                          000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                      000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!DeleteDC                                                                               000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!BitBlt                                                                                 000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!CreateDCW                                                                              000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!CreateDCA                                                                              000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!GetPixel                                                                               000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!StretchBlt                                                                             000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe[2148] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                 000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                            000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                 000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                         000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                      000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                            000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                    000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                     00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                  00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                       00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                  00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                          00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                      00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                         00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                   00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                       00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                              00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                             00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                   00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                               00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                         00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                       00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                   00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                  00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                  00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                            000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                  0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                            0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                             0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageW                                                      0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                               0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                   0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                    0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!PostMessageW                                                      0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!GetKeyState                                                       0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetParent                                                         0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                     0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!EnableWindow                                                      0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!MoveWindow                                                        0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!PostMessageA                                                      0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageA                                                      0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                             0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                 0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                              0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                               0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                 0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                               0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                               0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                  0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                  0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendInput                                                         0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                  0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                     0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!mouse_event                                                       0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!keybd_event                                                       0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                              0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!BlockInput                                                        0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                           0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                           00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!BitBlt                                                             0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                          0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                         000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                            000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!GetPixel                                                           000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                          000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                             0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                          0000000077141465 2 bytes [14, 77]
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                         00000000771414bb 2 bytes [14, 77]
.text     ...                                                                                                                                                                       * 2
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                              000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                   000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                           000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                        000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                              000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                      000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                       00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                    00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                         00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                    00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                            00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                        00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                           00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                     00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                         00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                               00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                     00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                 00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                           00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                         00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                     00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                    00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                    00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                              000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                    0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                  0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                               0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageW                                                        0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                 0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                     0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                      0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!PostMessageW                                                        0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!GetKeyState                                                         0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetParent                                                           0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                       0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!EnableWindow                                                        0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!MoveWindow                                                          0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!PostMessageA                                                        0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                  0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageA                                                        0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                               0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                   0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                  0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                 0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                   0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                  0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                 0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                 0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                    0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                    0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendInput                                                           0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                    0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                       0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!mouse_event                                                         0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!keybd_event                                                         0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                  0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!BlockInput                                                          0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                             0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2272] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                              0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                            00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                              00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                 00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                      00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                              00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                           00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                 00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                         00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                          00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                       00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                            00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                       00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                               00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                           00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                              00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                        00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                            00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                   00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                  00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                        00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                    00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                 00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\kernel32.dll!CreateProcessW                                                       00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\kernel32.dll!CreateProcessA                                                       000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                   000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                       000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!DeleteDC                                                                000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!BitBlt                                                                  000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!MaskBlt                                                                 000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!CreateDCW                                                               000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!CreateDCA                                                               000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!GetPixel                                                                000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!StretchBlt                                                              000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfdataexport.exe[2408] C:\Windows\system32\GDI32.dll!PlgBlt                                                                  000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                       00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                         00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                            00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                 00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                         00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                      00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                            00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                    00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                     00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                  00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                       00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                  00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                          00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                      00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                         00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                   00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                       00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                              00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                             00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                   00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                               00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                            00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\kernel32.dll!CreateProcessW                                                  00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\kernel32.dll!CreateProcessA                                                  000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                              000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                  000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!DeleteDC                                                           000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!BitBlt                                                             000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!MaskBlt                                                            000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!CreateDCW                                                          000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!CreateDCA                                                          000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!GetPixel                                                           000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!StretchBlt                                                         000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfindexingmanager.exe[2432] C:\Windows\system32\GDI32.dll!PlgBlt                                                             000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                  000000007789f9e0 5 bytes JMP 000000010028d080
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                       000000007789fcb0 5 bytes JMP 000000010029fac0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                               000000007789fd64 5 bytes JMP 000000010029dfa0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                            000000007789fdc8 5 bytes JMP 000000010029ec30
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                  000000007789fec0 5 bytes JMP 000000010029c270
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                          000000007789ffa4 5 bytes JMP 000000010029e640
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                           00000000778a0004 5 bytes JMP 000000010029ff20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                        00000000778a0084 5 bytes JMP 000000010029fce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                             00000000778a00b4 5 bytes JMP 000000010029e2a0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                        00000000778a03b8 5 bytes JMP 000000010029cc90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                00000000778a0550 5 bytes JMP 000000010029b520
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                            00000000778a0694 5 bytes JMP 000000010029f750
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                               00000000778a088c 5 bytes JMP 000000010029be90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                         00000000778a08a4 5 bytes JMP 000000010029c8f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                             00000000778a0df4 5 bytes JMP 000000010029f540
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                    00000000778a0ed8 5 bytes JMP 000000010029f0c0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                   00000000778a1be4 5 bytes JMP 000000010029f300
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                         00000000778a1cb4 5 bytes JMP 000000010029c520
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                     00000000778a1d8c 5 bytes JMP 000000010029eec0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                               00000000778bc4dd 5 bytes JMP 0000000100297df0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                             00000000778c1287 1 byte JMP 000000010028d1a0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                         00000000778c1289 5 bytes {JMP 0xffffffff889cbf19}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                        00000000772f103d 5 bytes JMP 0000000100294f30
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                        00000000772f1072 5 bytes JMP 0000000100295ac0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                  000000007731c9b5 5 bytes JMP 0000000100293a60
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                        0000000076c7f784 5 bytes JMP 000000010028d1d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                      0000000076ed8bff 5 bytes JMP 000000010028b640
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                   0000000076ed90d3 7 bytes JMP 000000010028c3d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageW                                                            0000000076ed9679 5 bytes JMP 000000010028b100
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                     0000000076ed97d2 5 bytes JMP 000000010028ab80
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                         0000000076edee09 5 bytes JMP 000000010028c0c0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                          0000000076edefc9 5 bytes JMP 00000001002880a0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!PostMessageW                                                            0000000076ee12a5 5 bytes JMP 000000010028bb80
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!GetKeyState                                                             0000000076ee291f 5 bytes JMP 0000000100289330
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetParent                                                               0000000076ee2d64 1 byte JMP 00000001002888e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                           0000000076ee2d66 3 bytes {JMP 0xffffffff893a5b7c}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!EnableWindow                                                            0000000076ee2da4 5 bytes JMP 0000000100287e00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!MoveWindow                                                              0000000076ee3698 5 bytes JMP 0000000100288b80
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!PostMessageA                                                            0000000076ee3baa 5 bytes JMP 000000010028be20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                      0000000076ee3c61 5 bytes JMP 000000010028b8e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageA                                                            0000000076ee612e 5 bytes JMP 000000010028b3a0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                   0000000076ee6c30 7 bytes JMP 000000010028c5f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                       0000000076ee7603 5 bytes JMP 000000010028c810
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                      0000000076ee7668 5 bytes JMP 000000010028a0c0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                    0000000076ee76e0 5 bytes JMP 000000010028a600
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                     0000000076ee781f 5 bytes JMP 000000010028ae40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                       0000000076ee835c 5 bytes JMP 000000010028ca80
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                      0000000076eec4b6 5 bytes JMP 00000001002886e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                     0000000076efc112 5 bytes JMP 0000000100289e10
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                     0000000076efd0f5 5 bytes JMP 0000000100289b60
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                        0000000076efeb96 5 bytes JMP 0000000100289080
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                        0000000076efec68 5 bytes JMP 00000001002895e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendInput                                                               0000000076efff4a 5 bytes JMP 0000000100289890
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                        0000000076f19f1d 5 bytes JMP 00000001002882d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                           0000000076f21497 5 bytes JMP 0000000100287bf0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!mouse_event                                                             0000000076f3027b 5 bytes JMP 0000000100299670
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!keybd_event                                                             0000000076f302bf 5 bytes JMP 0000000100299880
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                    0000000076f36cfc 5 bytes JMP 000000010028a8c0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                      0000000076f36d5d 5 bytes JMP 000000010028a360
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!BlockInput                                                              0000000076f37dd7 5 bytes JMP 00000001002884e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                 0000000076f388eb 5 bytes JMP 0000000100288e60
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                 00000000758458b3 5 bytes JMP 0000000100298bc0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                   0000000075845ea6 5 bytes JMP 00000001002993e0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                0000000075847bcc 5 bytes JMP 0000000100299cc0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                               000000007584b895 5 bytes JMP 0000000100298c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                  000000007584c332 5 bytes JMP 0000000100299130
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                 000000007584cbfb 5 bytes JMP 0000000100298990
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                000000007584e743 5 bytes JMP 0000000100299bc0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                   0000000075874857 5 bytes JMP 0000000100298ea0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x86\mfserveraux.exe[2460] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                  0000000077012642 5 bytes JMP 0000000100294390
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                 00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                   00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                      00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                           00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                   00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                      00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                              00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                               00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                            00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                 00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                            00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                    00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                   00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                             00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                 00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                        00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                       00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                             00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                         00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                      00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\kernel32.dll!CreateProcessW                                                            00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\kernel32.dll!CreateProcessA                                                            000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                        000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                            000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!DeleteDC                                                                     000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!BitBlt                                                                       000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!MaskBlt                                                                      000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!CreateDCW                                                                    000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!CreateDCA                                                                    000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!GetPixel                                                                     000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!StretchBlt                                                                   000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\GDI32.dll!PlgBlt                                                                       000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                      000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfsetup.exe[2576] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                  000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                   000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                        000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                             000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                   000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                           000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                            00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                         00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                              00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                         00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                 00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                             00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                          00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                              00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                     00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                    00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                          00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                      00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                              00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                          00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                         00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                         00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                   000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                         0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                   0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                       0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                    0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageW                                                             0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                      0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                          0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                           0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!PostMessageW                                                             0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!GetKeyState                                                              0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetParent                                                                0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                            0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!EnableWindow                                                             0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!MoveWindow                                                               0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!PostMessageA                                                             0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                       0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageA                                                             0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                    0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                        0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                       0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                     0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                      0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                        0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                       0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                      0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                      0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                         0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                         0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendInput                                                                0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                         0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                            0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!mouse_event                                                              0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!keybd_event                                                              0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                     0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                       0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!BlockInput                                                               0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                  0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                  00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                    0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                 0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                   000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                  000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                 000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe[2652] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                    0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[2692] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                             000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                  000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                          000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                       000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                             000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                     000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                      00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                   00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                        00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                   00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                           00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                       00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                          00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                    00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                        00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                               00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                              00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                    00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                          00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                        00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                    00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                   00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                   00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                             000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                   0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                             0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                 0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                              0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageW                                                       0000000076ed9679 5 bytes JMP 000000011001b100
 


  • 0

Advertisements


#17
bhzendner

bhzendner

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 219 posts

.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                    0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                     0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!PostMessageW                                                       0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!GetKeyState                                                        0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetParent                                                          0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                      0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!EnableWindow                                                       0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!MoveWindow                                                         0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!PostMessageA                                                       0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                 0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageA                                                       0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                              0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                  0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                 0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                               0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                  0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                 0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                   0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                   0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendInput                                                          0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                   0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                      0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!mouse_event                                                        0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!keybd_event                                                        0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                               0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                 0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!BlockInput                                                         0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                            0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                            00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!BitBlt                                                              0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                           0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                          000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                             000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!GetPixel                                                            000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                           000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe[2728] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                              0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                               00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                                     00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                                     000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                                 000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                                               000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Windows\system32\svchost.exe[2756] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                                           000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                           00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                             00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                     00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                             00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                          00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                        00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                         00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                      00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                           00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                      00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                              00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                          00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                             00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                       00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                           00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                  00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                 00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                       00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                   00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                      00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                      000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                  000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                      000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!DeleteDC                                                                               000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!BitBlt                                                                                 000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!CreateDCW                                                                              000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!CreateDCA                                                                              000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!GetPixel                                                                               000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!StretchBlt                                                                             000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe[2828] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                 000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                  00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                     00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                          00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                  00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                               00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                     00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                             00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                              00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                           00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                           00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                   00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                               00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                  00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                            00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                       00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                      00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                            00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                        00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                     00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\kernel32.dll!CreateProcessW                                                           00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\kernel32.dll!CreateProcessA                                                           000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                       000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                           000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!DeleteDC                                                                    000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!BitBlt                                                                      000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!MaskBlt                                                                     000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!CreateDCW                                                                   000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!CreateDCA                                                                   000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!GetPixel                                                                    000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!StretchBlt                                                                  000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\GDI32.dll!PlgBlt                                                                      000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                     000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\mfserver.exe[2600] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                 000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                                               000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                                           000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                               00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                 00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                    00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                         00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                 00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                              00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                    00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                            00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                             00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                          00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                               00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                          00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                  00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                              00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                 00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                           00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                               00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                      00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                     00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                           00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                       00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                    00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\kernel32.dll!CreateProcessW                                                          00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\kernel32.dll!CreateProcessA                                                          000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                      000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                          000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!DeleteDC                                                                   000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!BitBlt                                                                     000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!MaskBlt                                                                    000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!CreateDCW                                                                  000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!CreateDCA                                                                  000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!GetPixel                                                                   000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!StretchBlt                                                                 000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3904] C:\Windows\system32\GDI32.dll!PlgBlt                                                                     000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                               00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                 00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                    00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                         00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                 00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                              00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                    00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                            00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                             00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                          00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                               00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                          00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                  00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                              00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                 00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                           00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                               00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                      00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                     00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                           00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                       00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                    00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\kernel32.dll!CreateProcessW                                                          00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\kernel32.dll!CreateProcessA                                                          000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                      000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                          000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!DeleteDC                                                                   000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!BitBlt                                                                     000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!MaskBlt                                                                    000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!CreateDCW                                                                  000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!CreateDCA                                                                  000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!GetPixel                                                                   000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!StretchBlt                                                                 000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3912] C:\Windows\system32\GDI32.dll!PlgBlt                                                                     000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                               00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                 00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                    00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                         00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                 00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                              00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                    00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                            00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                             00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                          00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                               00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                          00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                  00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                              00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                 00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                           00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                               00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                      00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                     00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                           00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                       00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                    00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\kernel32.dll!CreateProcessW                                                          00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\kernel32.dll!CreateProcessA                                                          000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                      000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                          000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!DeleteDC                                                                   000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!BitBlt                                                                     000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!MaskBlt                                                                    000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!CreateDCW                                                                  000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!CreateDCA                                                                  000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!GetPixel                                                                   000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!StretchBlt                                                                 000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[3468] C:\Windows\system32\GDI32.dll!PlgBlt                                                                     000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                  00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                     00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                          00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                  00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                               00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                     00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                             00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                              00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                           00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                           00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                   00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                               00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                  00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                            00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                       00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                      00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                            00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                        00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                     00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\kernel32.dll!CreateProcessW                                                           00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\kernel32.dll!CreateProcessA                                                           000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                       000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                           000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!DeleteDC                                                                    000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!BitBlt                                                                      000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!MaskBlt                                                                     000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!CreateDCW                                                                   000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!CreateDCA                                                                   000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!GetPixel                                                                    000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!StretchBlt                                                                  000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFIndexer.exe[536] C:\Windows\system32\GDI32.dll!PlgBlt                                                                      000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                               00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                                     00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                                     000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                                 000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\System32\svchost.exe[4144] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\svchost.exe[4244] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                         00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                           00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                              00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                   00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                           00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                        00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                              00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                      00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                       00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                    00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                         00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                    00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                            00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                        00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                           00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                     00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                         00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                               00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                     00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                 00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                              00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                                    00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                                    000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                                000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                    000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                             000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!BitBlt                                                                                               000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                              000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                            000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                            000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!GetPixel                                                                                             000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                           000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\System32\WUDFHost.exe[4632] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                               000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                    000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                             000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!BitBlt                                                                                               000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                              000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                            000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                            000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!GetPixel                                                                                             000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                           000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\System32\WUDFHost.exe[4988] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                               000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                    00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                      00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                         00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                              00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                      00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                   00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                         00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                 00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                  00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                               00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                    00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                               00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                       00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                   00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                      00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                    00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                           00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                          00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                            00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                               000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                        000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!BitBlt                                                                                          000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                         000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                       000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                       000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!GetPixel                                                                                        000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                      000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\SearchIndexer.exe[4656] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                          000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                         00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                           00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                              00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                   00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                           00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                        00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                              00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                      00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                       00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                    00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                         00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                    00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                            00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                        00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                           00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                     00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                         00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                               00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                     00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                 00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                    000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                             000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!BitBlt                                                                                               000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                              000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                            000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                            000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!GetPixel                                                                                             000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                           000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                               000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA                                                                              000007fefdbea6f0 1 byte JMP 000007fffd3f0180
.text     C:\Windows\system32\taskhost.exe[3732] C:\Windows\system32\ADVAPI32.dll!CreateProcessAsUserA + 2                                                                          000007fefdbea6f2 5 bytes {JMP 0xffffffffff805a90}
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                              00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                                00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                   00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                        00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                             00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                   00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                           00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                            00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                         00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                              00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                         00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                 00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                             00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                          00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                              00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                     00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                    00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                          00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                      00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                         000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                  000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                    000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                   000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                 000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                 000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                  000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\Dwm.exe[1620] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                    000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                                  00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                                    00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                                       00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                            00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                                    00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                                 00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                                       00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                               00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                                00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                             00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                                  00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                             00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                                     00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                                 00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                                    00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                              00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                                  00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                         00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                        00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                              00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                          00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                                                       00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\kernel32.dll!CreateProcessW                                                                                             00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\kernel32.dll!CreateProcessA                                                                                             000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                                                         000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                                                             000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!DeleteDC                                                                                                      000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!BitBlt                                                                                                        000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!MaskBlt                                                                                                       000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!CreateDCW                                                                                                     000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!CreateDCA                                                                                                     000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!GetPixel                                                                                                      000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!StretchBlt                                                                                                    000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\GDI32.dll!PlgBlt                                                                                                        000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!RegisterRawInputDevices                                                                                      0000000077486ef0 8 bytes JMP 000000016fff06f8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SystemParametersInfoA                                                                                        0000000077488184 7 bytes JMP 000000016fff0880
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SetParent                                                                                                    0000000077488530 8 bytes JMP 000000016fff0730
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!PostMessageA                                                                                                 000000007748a404 5 bytes JMP 000000016fff0308
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!EnableWindow                                                                                                 000000007748aaa0 9 bytes JMP 000000016fff08f0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!MoveWindow                                                                                                   000000007748aad0 8 bytes JMP 000000016fff0768
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!GetAsyncKeyState                                                                                             000000007748c720 5 bytes JMP 000000016fff06c0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!RegisterHotKey                                                                                               000000007748cd50 8 bytes JMP 000000016fff0848
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!PostThreadMessageA                                                                                           000000007748d2b0 5 bytes JMP 000000016fff0378
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageA                                                                                                 000000007748d338 5 bytes JMP 000000016fff03e8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendNotifyMessageW                                                                                           000000007748dc40 9 bytes JMP 000000016fff0570
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SystemParametersInfoW                                                                                        000000007748f510 7 bytes JMP 000000016fff08b8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SetWindowsHookExW                                                                                            000000007748f874 9 bytes JMP 000000016fff0298
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageTimeoutW                                                                                          000000007748fac0 9 bytes JMP 000000016fff0490
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!PostThreadMessageW                                                                                           0000000077490b74 10 bytes JMP 000000016fff03b0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SetWinEventHook                                                                                              0000000077494d4c 5 bytes JMP 000000016fff02d0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!GetKeyState                                                                                                  0000000077495010 5 bytes JMP 000000016fff0688
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageCallbackW                                                                                         0000000077495438 7 bytes JMP 000000016fff0500
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageW                                                                                                 0000000077496b50 5 bytes JMP 000000016fff0420
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!PostMessageW                                                                                                 00000000774976e4 7 bytes JMP 000000016fff0340
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendDlgItemMessageW                                                                                          000000007749dd90 5 bytes JMP 000000016fff05e0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!GetClipboardData                                                                                             000000007749e874 5 bytes JMP 000000016fff0810
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SetClipboardViewer                                                                                           000000007749f780 8 bytes JMP 000000016fff07a0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendNotifyMessageA                                                                                           00000000774a28e4 12 bytes JMP 000000016fff0538
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!mouse_event                                                                                                  00000000774a3894 7 bytes JMP 000000016fff0228
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!GetKeyboardState                                                                                             00000000774a8a10 8 bytes JMP 000000016fff0650
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageTimeoutA                                                                                          00000000774a8be0 12 bytes JMP 000000016fff0458
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SetWindowsHookExA                                                                                            00000000774a8c20 12 bytes JMP 000000016fff0260
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendInput                                                                                                    00000000774a8cd0 8 bytes JMP 000000016fff0618
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!BlockInput                                                                                                   00000000774aad60 8 bytes JMP 000000016fff07d8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!ExitWindowsEx                                                                                                00000000774d14e0 5 bytes JMP 000000016fff0928
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!keybd_event                                                                                                  00000000774f45a4 7 bytes JMP 000000016fff01f0
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendDlgItemMessageA                                                                                          00000000774fcc08 5 bytes JMP 000000016fff05a8
.text     C:\Windows\Explorer.EXE[4748] C:\Windows\system32\USER32.dll!SendMessageCallbackA                                                                                         00000000774fdf18 7 bytes JMP 000000016fff04c8
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                     000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                          000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                  000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                               000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                     000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                             000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                              00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                           00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                           00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                   00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                               00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                  00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                            00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                       00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                      00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                            00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                        00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                  00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                            00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                           00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                           00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                     000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                           0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                         0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                      0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageW                                                               0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                        0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                            0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                             0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!PostMessageW                                                               0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetParent                                                                  0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                              0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!EnableWindow                                                               0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                 0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!PostMessageA                                                               0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                         0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageA                                                               0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                      0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                          0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                         0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                       0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                        0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                          0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                         0000000076eec4b6 5 bytes JMP 00000001100186e0
 


  • 0

#18
bhzendner

bhzendner

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 219 posts

.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                        0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                        0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                           0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                           0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendInput                                                                  0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                           0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                              0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!mouse_event                                                                0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!keybd_event                                                                0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                       0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                         0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!BlockInput                                                                 0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                    0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                    00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                      0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                   0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                  000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                     000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                    000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                   000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                      0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                     0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                   0000000077141465 2 bytes [14, 77]
.text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                  00000000771414bb 2 bytes [14, 77]
.text     ...                                                                                                                                                                       * 2
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                    00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                      00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                         00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                              00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                      00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                   00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                         00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                 00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                  00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                               00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                    00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                               00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                       00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                   00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                      00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                    00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                           00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                          00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                            00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                         00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\kernel32.dll!CreateProcessW                                                               00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\kernel32.dll!CreateProcessA                                                               000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                           000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                               000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!DeleteDC                                                                        000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!BitBlt                                                                          000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!MaskBlt                                                                         000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!CreateDCW                                                                       000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!CreateDCA                                                                       000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!GetPixel                                                                        000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!StretchBlt                                                                      000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe[4136] C:\Windows\system32\GDI32.dll!PlgBlt                                                                          000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                  00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                     00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                          00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                  00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                               00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                     00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                             00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                              00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                           00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                           00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                   00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                               00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                  00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                            00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                       00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                      00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                            00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                        00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\kernel32.dll!CreateProcessAsUserW                                                     00000000775898e0 12 bytes JMP 000000016fff01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\kernel32.dll!CreateProcessW                                                           00000000775a0650 12 bytes JMP 000000016fff0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\kernel32.dll!CreateProcessA                                                           000000007761acf0 1 byte JMP 000000016fff0180
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\kernel32.dll!CreateProcessA + 2                                                       000000007761acf2 5 bytes {JMP 0xfffffffff89d5490}
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\KERNELBASE.dll!SetProcessShutdownParameters                                           000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!DeleteDC                                                                    000007fefe3a22cc 5 bytes JMP 000007fffd3f02d0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!BitBlt                                                                      000007fefe3a24c0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!MaskBlt                                                                     000007fefe3a5bf0 5 bytes JMP 000007fffd3f0340
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!CreateDCW                                                                   000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!CreateDCA                                                                   000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!GetPixel                                                                    000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!StretchBlt                                                                  000007fefe3ab9f8 5 bytes JMP 000007fffd3f03b0
.text     C:\Program Files\M-Files\9.0.3372.41\Bin\x64\MFStatus.exe[1464] C:\Windows\system32\GDI32.dll!PlgBlt                                                                      000007fefe3ac8e0 5 bytes JMP 000007fffd3f0378
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                    000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                         000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                 000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                              000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                    000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                            000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                             00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                          00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                               00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                          00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                  00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                              00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                 00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                           00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                               00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                      00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                     00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                           00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                       00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                 00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                               00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                           00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                          00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                          00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                    000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                          0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                   00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                     0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                  0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                 000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                    000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                   000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                  000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                     0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                        0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                     0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageW                                                              0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                       0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                           0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                            0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!PostMessageW                                                              0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!GetKeyState                                                               0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetParent                                                                 0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                             0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!EnableWindow                                                              0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!PostMessageA                                                              0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                        0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageA                                                              0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                     0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                         0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                        0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                      0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                       0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                         0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                        0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                       0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                       0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                          0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                          0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendInput                                                                 0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                          0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                             0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!mouse_event                                                               0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!keybd_event                                                               0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                      0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                        0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!BlockInput                                                                0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                   0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                    0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                  0000000077141465 2 bytes [14, 77]
.text     C:\Users\MrZ\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[3940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                 00000000771414bb 2 bytes [14, 77]
.text     ...                                                                                                                                                                       * 2
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                                   000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                                        000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                                000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                             000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                                   000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                           000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                            00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                         00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                              00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                         00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                                 00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                             00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                                00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                          00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                              00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                                     00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                                    00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                          00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                                      00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                                00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                              00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                                          00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\KERNEL32.dll!CreateProcessW                                                                         00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\KERNEL32.dll!CreateProcessA                                                                         00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\KERNEL32.dll!CreateProcessAsUserW                                                                   000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                         0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                                   0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                                  00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                                    0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                                 0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                                000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                                   000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                                  000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                                 000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                                    0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                                       0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                                    0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                             0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                                      0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                          0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                           0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                             0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                              0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetParent                                                                                0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                                            0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                             0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                               0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                             0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                                       0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                             0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                                    0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                                        0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                                       0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                                     0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                                      0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                                        0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                                       0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                                      0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                                      0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                         0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                         0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendInput                                                                                0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                         0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                            0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!mouse_event                                                                              0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!keybd_event                                                                              0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                                     0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                                       0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!BlockInput                                                                               0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\MediaMall\PlayOn.exe[4124] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                                  0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                          00000000776c3b10 5 bytes JMP 000000016fff0110
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                            00000000776c7ac0 5 bytes JMP 000000016fff0d50
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtClose                                                                                               00000000776f13a0 8 bytes JMP 000000016fff00d8
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                                    00000000776f1570 8 bytes JMP 000000016fff0a78
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile                                                                                            00000000776f15e0 8 bytes JMP 000000016fff0c00
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                                                                                         00000000776f1620 8 bytes JMP 000000016fff0b90
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken                                                                               00000000776f16c0 8 bytes JMP 000000016fff0c38
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                                                                                       00000000776f1750 8 bytes JMP 000000016fff0b58
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                                                                                        00000000776f1790 8 bytes JMP 000000016fff0998
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                                                                                     00000000776f17e0 8 bytes JMP 000000016fff09d0
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile                                                                                          00000000776f1800 8 bytes JMP 000000016fff0bc8
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcConnectPort                                                                                     00000000776f19f0 8 bytes JMP 000000016fff0d18
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort                                                                             00000000776f1b00 8 bytes JMP 000000016fff0960
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtConnectPort                                                                                         00000000776f1bd0 8 bytes JMP 000000016fff0ab0
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSymbolicLinkObject                                                                            00000000776f1d20 8 bytes JMP 000000016fff0c70
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                                      00000000776f1d30 8 bytes JMP 000000016fff0ce0
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                                                                                          00000000776f20a0 8 bytes JMP 000000016fff0ae8
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtMakeTemporaryObject                                                                                 00000000776f2130 8 bytes JMP 000000016fff0ca8
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation                                                                                00000000776f29a0 8 bytes JMP 000000016fff0b20
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                                                                                      00000000776f2a20 8 bytes JMP 000000016fff0a08
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                                                                                  00000000776f2aa0 8 bytes JMP 000000016fff0a40
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\KERNELBASE.dll!SetProcessShutdownParameters                                                                     000007fefd5753c0 7 bytes JMP 000007fffd3f0148
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!DeleteDC                                                                                              000007fefe3a22cc 5 bytes JMP 000007fffd3f0260
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!BitBlt                                                                                                000007fefe3a24c0 5 bytes JMP 000007fffd3f0298
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!MaskBlt                                                                                               000007fefe3a5bf0 5 bytes JMP 000007fffd3f02d0
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!CreateDCW                                                                                             000007fefe3a8398 9 bytes JMP 000007fffd3f01f0
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!CreateDCA                                                                                             000007fefe3a89d8 9 bytes JMP 000007fffd3f01b8
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!GetPixel                                                                                              000007fefe3a9344 5 bytes JMP 000007fffd3f0228
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!StretchBlt                                                                                            000007fefe3ab9f8 5 bytes JMP 000007fffd3f0340
.text     C:\Windows\system32\AUDIODG.EXE[5848] C:\Windows\System32\GDI32.dll!PlgBlt                                                                                                000007fefe3ac8e0 5 bytes JMP 000007fffd3f0308
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                                          000000007789f9e0 5 bytes JMP 000000010030d080
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                               000000007789fcb0 5 bytes JMP 000000010031fac0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                                                       000000007789fd64 5 bytes JMP 000000010031dfa0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                                                    000000007789fdc8 5 bytes JMP 000000010031ec30
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                                          000000007789fec0 5 bytes JMP 000000010031c270
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                                                  000000007789ffa4 5 bytes JMP 000000010031e640
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                                                   00000000778a0004 5 bytes JMP 000000010031ff20
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                                                00000000778a0084 5 bytes JMP 000000010031fce0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                                                     00000000778a00b4 5 bytes JMP 000000010031e2a0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                                                00000000778a03b8 5 bytes JMP 000000010031cc90
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                                                        00000000778a0550 5 bytes JMP 000000010031b520
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                                                    00000000778a0694 5 bytes JMP 000000010031f750
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                                                       00000000778a088c 5 bytes JMP 000000010031be90
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                                                 00000000778a08a4 5 bytes JMP 000000010031c8f0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                                                     00000000778a0df4 5 bytes JMP 000000010031f540
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                                            00000000778a0ed8 5 bytes JMP 000000010031f0c0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                                           00000000778a1be4 5 bytes JMP 000000010031f300
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                                                 00000000778a1cb4 5 bytes JMP 000000010031c520
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                                             00000000778a1d8c 5 bytes JMP 000000010031eec0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                       00000000778bc4dd 5 bytes JMP 0000000100317df0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                     00000000778c1287 1 byte JMP 000000010030d1a0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                                                 00000000778c1289 5 bytes {JMP 0xffffffff88a4bf19}
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                                                00000000772f103d 5 bytes JMP 0000000100314f30
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                                                00000000772f1072 5 bytes JMP 0000000100315ac0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                                          000000007731c9b5 5 bytes JMP 0000000100313a60
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                                                0000000076c7f784 5 bytes JMP 000000010030d1d0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                                              0000000076ed8bff 5 bytes JMP 000000010030b640
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                                           0000000076ed90d3 7 bytes JMP 000000010030c3d0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageW                                                                    0000000076ed9679 5 bytes JMP 000000010030b100
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                                             0000000076ed97d2 5 bytes JMP 000000010030ab80
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                 0000000076edee09 5 bytes JMP 000000010030c0c0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                                                  0000000076edefc9 5 bytes JMP 00000001003080a0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!PostMessageW                                                                    0000000076ee12a5 5 bytes JMP 000000010030bb80
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!GetKeyState                                                                     0000000076ee291f 5 bytes JMP 0000000100309330
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetParent                                                                       0000000076ee2d64 1 byte JMP 00000001003088e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetParent + 2                                                                   0000000076ee2d66 3 bytes {JMP 0xffffffff89425b7c}
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!EnableWindow                                                                    0000000076ee2da4 5 bytes JMP 0000000100307e00
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!MoveWindow                                                                      0000000076ee3698 5 bytes JMP 0000000100308b80
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!PostMessageA                                                                    0000000076ee3baa 5 bytes JMP 000000010030be20
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                                              0000000076ee3c61 5 bytes JMP 000000010030b8e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageA                                                                    0000000076ee612e 5 bytes JMP 000000010030b3a0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                                           0000000076ee6c30 7 bytes JMP 000000010030c5f0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                               0000000076ee7603 5 bytes JMP 000000010030c810
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                                              0000000076ee7668 5 bytes JMP 000000010030a0c0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                                            0000000076ee76e0 5 bytes JMP 000000010030a600
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                                             0000000076ee781f 5 bytes JMP 000000010030ae40
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                               0000000076ee835c 5 bytes JMP 000000010030ca80
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                                              0000000076eec4b6 5 bytes JMP 00000001003086e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                                             0000000076efc112 5 bytes JMP 0000000100309e10
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                                             0000000076efd0f5 5 bytes JMP 0000000100309b60
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                                                0000000076efeb96 5 bytes JMP 0000000100309080
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                                                0000000076efec68 5 bytes JMP 00000001003095e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendInput                                                                       0000000076efff4a 5 bytes JMP 0000000100309890
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!GetClipboardData                                                                0000000076f19f1d 5 bytes JMP 00000001003082d0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                                                   0000000076f21497 5 bytes JMP 0000000100307bf0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!mouse_event                                                                     0000000076f3027b 5 bytes JMP 0000000100319670
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!keybd_event                                                                     0000000076f302bf 5 bytes JMP 0000000100319880
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                                            0000000076f36cfc 5 bytes JMP 000000010030a8c0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                                              0000000076f36d5d 5 bytes JMP 000000010030a360
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!BlockInput                                                                      0000000076f37dd7 5 bytes JMP 00000001003084e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                                                         0000000076f388eb 5 bytes JMP 0000000100308e60
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!DeleteDC                                                                         00000000758458b3 5 bytes JMP 0000000100318bc0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!BitBlt                                                                           0000000075845ea6 5 bytes JMP 00000001003193e0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!CreateDCA                                                                        0000000075847bcc 5 bytes JMP 0000000100319cc0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!StretchBlt                                                                       000000007584b895 5 bytes JMP 0000000100318c00
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                                          000000007584c332 5 bytes JMP 0000000100319130
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!GetPixel                                                                         000000007584cbfb 5 bytes JMP 0000000100318990
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!CreateDCW                                                                        000000007584e743 5 bytes JMP 0000000100319bc0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                                           0000000075874857 5 bytes JMP 0000000100318ea0
.text     C:\Program Files (x86)\Eye-Fi\Helper\EyeFiHelper.exe[1448] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                                          0000000077012642 5 bytes JMP 0000000100314390
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtClose                                                000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                     000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                             000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                          000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                                000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                        000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                         00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                      00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                           00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                      00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                              00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                          00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                             00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                       00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                           00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                                  00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                                 00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                       00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                   00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                             00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                           00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                       00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                      00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                      00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                                000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                      0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                                0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!DeleteDC                                               00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!BitBlt                                                 0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!CreateDCA                                              0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!StretchBlt                                             000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!MaskBlt                                                000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!GetPixel                                               000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!CreateDCW                                              000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\GDI32.dll!PlgBlt                                                 0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                    0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                                 0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageW                                          0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                   0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                       0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                        0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!PostMessageW                                          0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!GetKeyState                                           0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetParent                                             0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetParent + 2                                         0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!EnableWindow                                          0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!MoveWindow                                            0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!PostMessageA                                          0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                    0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageA                                          0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                                 0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                     0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                    0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                                  0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                   0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                     0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SetClipboardViewer                                    0000000076eec4b6 5 bytes JMP 00000001100186e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageA                                   0000000076efc112 5 bytes JMP 0000000110019e10
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendDlgItemMessageW                                   0000000076efd0f5 5 bytes JMP 0000000110019b60
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!GetAsyncKeyState                                      0000000076efeb96 5 bytes JMP 0000000110019080
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!GetKeyboardState                                      0000000076efec68 5 bytes JMP 00000001100195e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendInput                                             0000000076efff4a 5 bytes JMP 0000000110019890
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!GetClipboardData                                      0000000076f19f1d 5 bytes JMP 00000001100182d0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!ExitWindowsEx                                         0000000076f21497 5 bytes JMP 0000000110017bf0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!mouse_event                                           0000000076f3027b 5 bytes JMP 0000000110029670
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!keybd_event                                           0000000076f302bf 5 bytes JMP 0000000110029880
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendMessageCallbackA                                  0000000076f36cfc 5 bytes JMP 000000011001a8c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!SendNotifyMessageA                                    0000000076f36d5d 5 bytes JMP 000000011001a360
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!BlockInput                                            0000000076f37dd7 5 bytes JMP 00000001100184e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5308] C:\Windows\syswow64\USER32.dll!RegisterRawInputDevices                               0000000076f388eb 5 bytes JMP 0000000110018e60
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtClose                                             000000007789f9e0 5 bytes JMP 000000011001d080
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                  000000007789fcb0 5 bytes JMP 000000011002fac0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile                                          000000007789fd64 5 bytes JMP 000000011002dfa0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtOpenSection                                       000000007789fdc8 5 bytes JMP 000000011002ec30
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtAdjustPrivilegesToken                             000000007789fec0 5 bytes JMP 000000011002c270
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection                                     000000007789ffa4 5 bytes JMP 000000011002e640
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtCreateThread                                      00000000778a0004 5 bytes JMP 000000011002ff20
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtTerminateThread                                   00000000778a0084 5 bytes JMP 000000011002fce0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile                                        00000000778a00b4 5 bytes JMP 000000011002e2a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtAlpcConnectPort                                   00000000778a03b8 5 bytes JMP 000000011002cc90
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtAlpcSendWaitReceivePort                           00000000778a0550 5 bytes JMP 000000011002b520
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtConnectPort                                       00000000778a0694 5 bytes JMP 000000011002f750
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject                          00000000778a088c 5 bytes JMP 000000011002be90
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtCreateThreadEx                                    00000000778a08a4 5 bytes JMP 000000011002c8f0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtLoadDriver                                        00000000778a0df4 5 bytes JMP 000000011002f540
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtMakeTemporaryObject                               00000000778a0ed8 5 bytes JMP 000000011002f0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtSetSystemInformation                              00000000778a1be4 5 bytes JMP 000000011002f300
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtShutdownSystem                                    00000000778a1cb4 5 bytes JMP 000000011002c520
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!NtSystemDebugControl                                00000000778a1d8c 5 bytes JMP 000000011002eec0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                          00000000778bc4dd 5 bytes JMP 0000000110027df0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                        00000000778c1287 1 byte JMP 000000011001d1a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll + 2                                    00000000778c1289 5 bytes {JMP 0xffffffff9875bf19}
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\kernel32.dll!CreateProcessW                                   00000000772f103d 5 bytes JMP 0000000110024f30
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\kernel32.dll!CreateProcessA                                   00000000772f1072 5 bytes JMP 0000000110025ac0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\kernel32.dll!CreateProcessAsUserW                             000000007731c9b5 5 bytes JMP 0000000110023a60
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\KERNELBASE.dll!SetProcessShutdownParameters                   0000000076c7f784 5 bytes JMP 000000011001d1d0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA                             0000000077012642 5 bytes JMP 0000000110024390
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!DeleteDC                                            00000000758458b3 5 bytes JMP 0000000110028bc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!BitBlt                                              0000000075845ea6 5 bytes JMP 00000001100293e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!CreateDCA                                           0000000075847bcc 5 bytes JMP 0000000110029cc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!StretchBlt                                          000000007584b895 5 bytes JMP 0000000110028c00
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!MaskBlt                                             000000007584c332 5 bytes JMP 0000000110029130
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!GetPixel                                            000000007584cbfb 5 bytes JMP 0000000110028990
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!CreateDCW                                           000000007584e743 5 bytes JMP 0000000110029bc0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\GDI32.dll!PlgBlt                                              0000000075874857 5 bytes JMP 0000000110028ea0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!PostThreadMessageW                                 0000000076ed8bff 5 bytes JMP 000000011001b640
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SystemParametersInfoW                              0000000076ed90d3 7 bytes JMP 000000011001c3d0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendMessageW                                       0000000076ed9679 5 bytes JMP 000000011001b100
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutW                                0000000076ed97d2 5 bytes JMP 000000011001ab80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                    0000000076edee09 5 bytes JMP 000000011001c0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!RegisterHotKey                                     0000000076edefc9 5 bytes JMP 00000001100180a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!PostMessageW                                       0000000076ee12a5 5 bytes JMP 000000011001bb80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!GetKeyState                                        0000000076ee291f 5 bytes JMP 0000000110019330
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetParent                                          0000000076ee2d64 1 byte JMP 00000001100188e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetParent + 2                                      0000000076ee2d66 3 bytes {JMP 0xffffffff99135b7c}
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!EnableWindow                                       0000000076ee2da4 5 bytes JMP 0000000110017e00
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!MoveWindow                                         0000000076ee3698 5 bytes JMP 0000000110018b80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!PostMessageA                                       0000000076ee3baa 5 bytes JMP 000000011001be20
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!PostThreadMessageA                                 0000000076ee3c61 5 bytes JMP 000000011001b8e0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendMessageA                                       0000000076ee612e 5 bytes JMP 000000011001b3a0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SystemParametersInfoA                              0000000076ee6c30 7 bytes JMP 000000011001c5f0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                  0000000076ee7603 5 bytes JMP 000000011001c810
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendNotifyMessageW                                 0000000076ee7668 5 bytes JMP 000000011001a0c0
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendMessageCallbackW                               0000000076ee76e0 5 bytes JMP 000000011001a600
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SendMessageTimeoutA                                0000000076ee781f 5 bytes JMP 000000011001ae40
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                  0000000076ee835c 5 bytes JMP 000000011001ca80
.text     C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[3752] C:\Windows\syswow64\USER32.dll!SetClipboardViewer